Class: CMSScanner::Target

Inherits:
WebSite
  • Object
show all
Includes:
Server::Generic
Defined in:
lib/cms_scanner/target.rb,
lib/cms_scanner/target/server/iis.rb,
lib/cms_scanner/target/platform/php.rb,
lib/cms_scanner/target/server/apache.rb,
lib/cms_scanner/target/server/generic.rb,
lib/cms_scanner/target/platform/wordpress.rb,
lib/cms_scanner/target/platform/wordpress/custom_directories.rb

Overview

Target to Scan

Defined Under Namespace

Modules: Platform, Server

Instance Attribute Summary

Attributes inherited from WebSite

#uri

Instance Method Summary collapse

Methods included from Server::Generic

#headers, #server

Methods inherited from WebSite

#http_auth?, #initialize, #online?, #proxy_auth?, #redirection, #url, #url=

Constructor Details

This class inherits a constructor from CMSScanner::WebSite

Instance Method Details

#in_scope?(url) ⇒ Boolean

Note:

Subdomains are considered out of scope (maybe consider them in ?) Also, // are handled by Addressable::URI, but worngly :/ e.g: Addressable::URI.parse('//file').host => file

Returns true if the url given belongs to the target.

Parameters:

  • url (String)

Returns:

  • (Boolean) —

    true if the url given belongs to the target



16
17
18
19
20
21
22
# File 'lib/cms_scanner/target.rb', line 16

def in_scope?(url)
  return true if url[0, 1] == '/' && url[1, 1] != '/'

  Addressable::URI.parse(url).host == uri.host
rescue
  false
end

#interesting_files(opts = {}) ⇒ Findings

TODO: add a force option to re-call the #find rather than return the @interesting_files ?

Parameters:

  • opts (Hash) (defaults to: {})

Returns:

  • (Findings)


29
30
31
# File 'lib/cms_scanner/target.rb', line 29

def interesting_files(opts = {})
  @interesting_files ||= NS::Finders::InterestingFiles.find(self, opts)
end