From 2f4838cdb36b1573f2879011ee677eeff7b19e4e Mon Sep 17 00:00:00 2001 From: Charles BLANC-ROLIN <58611524+woundride@users.noreply.github.com> Date: Thu, 28 Jan 2021 22:37:42 +0100 Subject: [PATCH] News informations (#53) * News informations Informations about SPIP, GLPI and PACS NGI GXD5 * Update chopchop.yml News informations added : AudioCodes SIP Gateway Xerox Printer Lexmark Printer Aklia Lisis --- .github/workflows/build.yml | 2 +- .github/workflows/docker-publish.yml | 2 +- .github/workflows/lint.yml | 4 +- chopchop.yml | 144 ++++++++++++++------------- 4 files changed, 81 insertions(+), 71 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 502a6c9..b018957 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -11,7 +11,7 @@ jobs: - name: Checkout code uses: actions/checkout@v2 - name: Unit Tests - uses: go test ./... + run: go test ./... - name: Install gox run: go get github.com/mitchellh/gox - name: Build using gox diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index aaccabe..fe50703 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -50,7 +50,7 @@ jobs: go-version: 1.14.x - uses: actions/checkout@v2 - name: Unit Tests - uses: go test ./... + run: go test ./... - name: Build image run: docker build . --file Dockerfile --tag $IMAGE_NAME diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 7643285..59f77fd 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -18,5 +18,5 @@ jobs: - uses: actions/checkout@v1 - run: | cat chopchop.yml | grep "uri:" | sort | uniq -c | sort -n - test=`cat chopchop.yml | grep "uri:" | sort | uniq -c | grep -v 1 | wc -l` - if [ $test != 0 ]; then echo "There shouldn't be multiple (and identical) 'uri'. It should be refactored. "; exit 1; fi + test=`cat chopchop.yml | grep "endpoint:" | sort | uniq -c | grep -v 1 | wc -l` + if [ $test != 0 ]; then echo "There shouldn't be multiple (and identical) 'endpoint'. It should be refactored. "; exit 1; fi diff --git a/chopchop.yml b/chopchop.yml index 51cdbf9..41b52f9 100644 --- a/chopchop.yml +++ b/chopchop.yml @@ -9,9 +9,32 @@ plugins: remediation: Make sure that GENEREX UPS access is restricted & monitored description: GENEREX UPS is accessible | don't move this rule to avoid client timeout severity: "Medium" - tested: true - endpoint: "/" checks: + - name : GLPI vulnerable version + match: + - 'GLPI - Authentification' + - 'title="Powered by Teclib and contributors" class="copyright">GLPI Copyright' + no_match : + - 'src="/public/lib/base.min.js?v=9.5.3"' + remediation: Upgrade GLPI in latest version + description: GLPI vulnerable version detected + status_code: 200 + severity: "High" + - name : PACS NGI GXD5 + match: + - 'GXD5 Pacs Connexion utilisateur' + remediation: Make sure that PACS NGI GXD5 access is restricted & monitored + description: PACS NGI GXD5 detected + status_code: 200 + severity: "High" + - name: AudioCodes SIP Gateway + match: + - 'AudioCodes' + - '

Web Login

' + remediation: Make sure that AudioCodes SIP Gateway access is restricted & monitored + description: AudioCodes SIP Gateway detected + severity: "Informational" - name: HP Printer headers: - "Server:Virata-EmWeb/R6_2_1" @@ -19,7 +42,6 @@ plugins: description: HP Printer is accessible status_code: 200 severity: "Low" - tested: true - name: Printer (Lexmark, Dell, Toshiba, Sindoh) headers: - "Server:Lexmark_Web_Server" @@ -46,7 +68,6 @@ plugins: description: GE ViewPoint System Status is accessible / sensitive information leaking status_code: 200 severity: "Low" - tested: true - name: Ascom IP-DECT Base Station match: - '