Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/ronin-rb/ronin-vulns

Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects.
https://github.com/ronin-rb/ronin-vulns

Add ruby-3.3 to the CI matrix.

6aee0fa1652fc4885ccc8af83f330b9e5bd6fd3e authored about 1 year ago by Postmodern <[email protected]>
Use `Hash#each_value` to make `rubocop` happy.

52e5b2ad26b99c586e2091b46084411b2dae1d09 authored about 1 year ago by Postmodern <[email protected]>
Added a top-level example to `URLScanner`.

3774c6197960d85bf1a6033d6ac005d7d073a1ac authored about 1 year ago by Postmodern <[email protected]>
Vertically align `let` blocks.

9fa24c67c008c1d15e6d299ea9093498194307ef authored about 1 year ago by Postmodern <[email protected]>
Bump the `actions/checkout` action to `v4`.

4da9771c6cc3cf9400ff8dba534be8f827487d77 authored over 1 year ago by Postmodern <[email protected]>
Version bump to 0.1.4.

720dd5ed40e0fc06897b5f8ad160dcfc09bdc884 authored over 1 year ago by Postmodern <[email protected]>
Updated the ChangeLog for 0.1.4.

7fcdbc847f1493f95a00a593bbe5b7a680910de4 authored over 1 year ago by Postmodern <[email protected]>
Fixed YARD links.

c6d2971e8d4e9899091f10f36e4b2b0203dd174b authored over 1 year ago by Postmodern <[email protected]>
Print the vulnerable param name in single quotes.

7cd8e7f28ae281285c7cba2300d51324cff685b2 authored over 1 year ago by Postmodern <[email protected]>
Make `CLI::WebVulnCommand#scan_kwargs` an instance variable (closes #49).

* This should slightly improve the performance of `ronin-vulns`
commands, as the `scan_kwargs`...

e23c811392855ee686979508c30b3e128a7ffc83 authored over 1 year ago by Postmodern <[email protected]>
Use more explicit code.

60f87906d04bc9d16092149a2fc8c9510901ccf7 authored over 1 year ago by Postmodern <[email protected]>
Allow `--cookie` to be repeated multiple times and merge the values.

* Removed `CLI::WebVulnCommand#raw_cookie`.

b82512a9e53f7a42bec93b2e526cd9c7e7250824 authored over 1 year ago by Postmodern <[email protected]>
Removed the Twitter account link.

7e468b61a5049c1009362bbe0a7a1ff5bfd5c1c8 authored over 1 year ago by Postmodern <[email protected]>
Updated the ChangeLog for 0.1.3.

45deabd6eb4efad460d4a30d92931496a7e602a0 authored over 1 year ago by Postmodern <[email protected]>
Exclude the man-pages from `.document`.

d066cfa7e124406a153d0810dd1c2e3a75a3d9f2 authored over 1 year ago by Postmodern <[email protected]>
Use single quotes.

988f1a02b522240a94167507e8fdc350518165ce authored over 1 year ago by Postmodern <[email protected]>
Refactored `SQLI.scan` and `SSTI.scan` to accept explicit keyword args.

20333057bccee8c8a455306092e3b580c02b2854 authored over 1 year ago by Postmodern <[email protected]>
Detect XSS inside or after HTML comments

17113cf25beb0fa6c3f14688966d43b064bbd877 authored over 1 year ago by Milo Winningham <[email protected]>
Add missing specs when keyword arguments are given to `SQLI.scan`.

1da7676b6e525f63b8f886b62dc316daf2f0baa8 authored over 1 year ago by Postmodern <[email protected]>
Fix rubocop warnings.

e508b77a319172d3d5c0ba39644c2a153b847629 authored over 1 year ago by Postmodern <[email protected]>
Added missing specs for `SQLI.scan`.

ca8ba4fab2728a5229c6e152631189ccd7981132 authored over 1 year ago by Postmodern <[email protected]>
Style.

eda2b0142bdc0473e6580069d65a1d66350fbcae authored over 1 year ago by Postmodern <[email protected]>
Version bump to 0.1.3.

1015c9e140abe4347a1cbc16dcb0639de049aa3e authored over 1 year ago by Postmodern <[email protected]>
Fixed a bug in `SQLI.scan` where repeat requests would be sent.

* If `escape_quote:`, `escape_parens:`, or `terminate:` are given,
duplicate requests would be...

03f951d64018d162973fa7e189fd5b5355065f53 authored over 1 year ago by Postmodern <[email protected]>
Fixed a bug where `SSTI.scan` without `escape:` would not return all vulns.

6ec9247d87683c6fd8cb864ac9b8c24043c1e245 authored over 1 year ago by Postmodern <[email protected]>
Fixed YARD class names.

3d7dbf6ba3b75064bc8d58e96c95b32860c8429e authored over 1 year ago by Postmodern <[email protected]>
Updated the ChangeLog for 0.1.2.

ac58114d3a2745b1a058ab05acb06b58afc6d178 authored almost 2 years ago by Postmodern <[email protected]>
Require `ronin-support` ~> 1.0, >= 1.0.1.

344280e9263596a5405cfa09d126193c15b8d261 authored almost 2 years ago by Postmodern <[email protected]>
Version bump to 0.1.2.

2b4427dd1aac61be6db8001e7fc37577c273d187 authored almost 2 years ago by Postmodern <[email protected]>
Print a message if no vulnerabilities were discovered.

e04790180bf2bc05ae8fd7ed881b52789e681c0b authored almost 2 years ago by Postmodern <[email protected]>
Add validations to ensure URLs start with `http://` or `https://` (closes #38).

75f7f67db60f9f0c6d8e8a39df9e27ba68cf45c2 authored almost 2 years ago by Postmodern <[email protected]>
Various `rubocop` style changes.

a4ccc58615e5877e21de625df043cd5c1b045ace authored almost 2 years ago by Postmodern <[email protected]>
Removed old `rubygems` requirement.

cbf175f799b6995cec81790391e592e4b01d59f6 authored almost 2 years ago by Postmodern <[email protected]>
Added missing `frozen_string_literal: true` magic comments.

b3abe0cfdb46f6d4acaceaad1f7e040b35e904c8 authored almost 2 years ago by Postmodern <[email protected]>
Added a top-level description to `Ronin::Vulns::CLI::Logging`.

9e99c10cbf071e773d9308444fb1b544e1c8a00e authored almost 2 years ago by Postmodern <[email protected]>
Make an excepton for `Ronin::Vulns::WebVuln` and `Lint/MissingSuper`.

e72bc8e93eaffca4d3dd04d4e2d16b45a98f4131 authored almost 2 years ago by Postmodern <[email protected]>
Use the new `rubocop-ronin` gem for shared configuration.

d6884f8b20b12b9605b1be5cfe61808cfc8a5e62 authored almost 2 years ago by Postmodern <[email protected]>
Added a top-level description to `URLScanner`.

f8a6d61809e1710c89b8eb2379b3b99a5c61b846 authored almost 2 years ago by Postmodern <[email protected]>
Also convert `merged_url` into a `let()`.

c25cf51657e76e0189fe032f2e488a44698720e9 authored almost 2 years ago by Postmodern <[email protected]>
Use `Object#tap` here.

efa37fcf368cbab7d917f2f86159577eb541bff7 authored almost 2 years ago by Postmodern <[email protected]>
Convert the local variable into a `let()`.

5f6c664227c716e2bf0046dd751249dde9a09023 authored almost 2 years ago by Postmodern <[email protected]>
Add rubocop to the CI (closes #31).

64d75ad2ba2fc4ac0c72ae1c8497d18b9fb5a661 authored almost 2 years ago by Postmodern <[email protected]>
Add rubocop exceptions for specific spots.

f400a45acf7062b4173b9aeaba281eba329d2aea authored almost 2 years ago by Postmodern <[email protected]>
Indent HEREDocs by two spaces.

112dfcf583c9190b5bed02f055c5661ef64b5404 authored almost 2 years ago by Postmodern <[email protected]>
Fix indentation.

1c29392e2d710cfe8e5e9aa6867214d73a6b80ae authored almost 2 years ago by Postmodern <[email protected]>
Inline `rescue`s into the block.

4f0c6ea959b00d0e4ad8c4c5a9cb4bbc97e99da4 authored almost 2 years ago by Postmodern <[email protected]>
Add parenthesis to `exit -1`.

2a26a577b9b806fb1ecbb294f0fa97a3b19e3c74 authored almost 2 years ago by Postmodern <[email protected]>
Remove duplicate magic comments.

0dced2ad768bb1808a6984cc358bfca8744fd89f authored almost 2 years ago by Postmodern <[email protected]>
`rand(Range)` is technically slightly faster than `rand(N) + B`.

20280ad46e90d4a5ef65b6cce36670670a02dc17 authored almost 2 years ago by Postmodern <[email protected]>
Single quote literal strings.

f771982ea5fa12e16d6e86ebdcfa95fc324fcc4b authored almost 2 years ago by Postmodern <[email protected]>
Shorten the empty blocks to one line.

c189b9cc10a04eff0aa6216086040ae4b04d3b29 authored almost 2 years ago by Postmodern <[email protected]>
Remove empty lines.

06ffa885cebdfa3a697eb6ac69a7ab08ead04558 authored almost 2 years ago by Postmodern <[email protected]>
Added the stock `.rubocop.yml` file from `ronin-template` (issue #31).

d66f5a8150857ddfc1b7e5a165f8059df80c00a0 authored almost 2 years ago by Postmodern <[email protected]>
Added the `rubocop` gem (issue #31).

5f036820e50e20653a44b7142eb1c6068ff2fa70 authored almost 2 years ago by Postmodern <[email protected]>
Updated the ChangeLog for 0.1.1.

8ea44f5aff20f6b58d064d7fcb8b1d67ffad69f6 authored almost 2 years ago by Postmodern <[email protected]>
Fix stub specs.

2633fde303b2b0432020007f2178c3896036919b authored almost 2 years ago by Postmodern <[email protected]>
Bump version to 0.1.1.

4fd0feb0e33298cc8dfe2d9540bc9cc79fded16e authored almost 2 years ago by Postmodern <[email protected]>
Use `log_vuln` instead of non-existent `print_vuln` method (closes #34).

491e4d0c3f2c331ba92b4f73f1bf1af2a991cb54 authored almost 2 years ago by Postmodern <[email protected]>
Updated the copyright years.

682269f10f7619f5979f2ffb2f76ad9c58fc2b1d authored almost 2 years ago by Postmodern <[email protected]>
Only install sord and stackprof when on CRuby.

e1207e448a9fdbbaf4484060b7f8831dee64825f authored almost 2 years ago by Postmodern <[email protected]>
Fixed the release date for 0.1.0.

b121dc840d35f9135ae9966a6d0cf4522178d175 authored almost 2 years ago by Postmodern <[email protected]>
Version bump to 0.1.0.

52a5c35c4192569786a11bbbbec973bb1a496293 authored almost 2 years ago by Postmodern <[email protected]>
Require ronin-core ~> 0.1.

891c6050a976522ce11c94ba81055140f80c02cd authored almost 2 years ago by Postmodern <[email protected]>
Require ronin-support ~> 1.0.

f1b1b4f35feeb23a3c01273efaf1ed1c20735abd authored almost 2 years ago by Postmodern <[email protected]>
Fixed spelling mistakes in the man pages and option descriptions.

ade2e5f32ef6c96c3072f8b62b1f303b745c5443 authored almost 2 years ago by Postmodern <[email protected]>
Fixed spelling mistakes in the documentation.

6bcb84d63d5e700b0de40486c79cc9d67f0e99c3 authored almost 2 years ago by Postmodern <[email protected]>
Added specs for `ronin-vulns` man pages.

79bc9bcf3c95f84e36de486bf191bf29601378cb authored almost 2 years ago by Postmodern <[email protected]>
Added a gem version badge.

3a1ca4f5faa2ac3cf954771dc552c89af7aa904d authored almost 2 years ago by Postmodern <[email protected]>
Cache gems.

451f5beafcd3490666c9ea1619ea16d30bc0b76c authored almost 2 years ago by Postmodern <[email protected]>
No longer set `gemspec.test_files`.

885081b64745ac2aee87b30b9d19cba7cde83ace authored about 2 years ago by Postmodern <[email protected]>
Link to the library namespace in the YARDocs title.

4bfc887cea1c6f855f7413e1a0aa374461cfc4f0 authored about 2 years ago by Postmodern <[email protected]>
Link to the `main` branch.

63a7f93398d8e24729b27e3ffa18567b83467f5a authored about 2 years ago by Postmodern <[email protected]>
Changed the gem's documentation URL.

c063902bc94582bc3b336ee8591fb30cf0a9e8b0 authored about 2 years ago by Postmodern <[email protected]>
Ensure that `ronin-vulns --version` prints the version.

cc7adfe748e6093a53ee1e3fab62633862782127 authored about 2 years ago by Postmodern <[email protected]>
Remove duplicate "and".

789cf4bc442ab7955a5e97ae6d4d757b0e0afb66 authored about 2 years ago by Postmodern <[email protected]>
Updated/fixed the copyright years.

8586928177b7ae8a57acfd9ec9f0119a2c50f911 authored about 2 years ago by Postmodern <[email protected]>
Switched to ronin-core 0.1.0.beta1.

c88f974fcebdb6e202d09aeb0b8e7780836f4cbe authored about 2 years ago by Postmodern <[email protected]>
Switched to ronin-support 1.0.0.beta1.

7eec3f63584cebd3adbd3d4736dcfeba45f24c99 authored about 2 years ago by Postmodern <[email protected]>
Added a ChangeLog.

22211af4c1cfd6ef9852561fa5a13d3ad526f399 authored about 2 years ago by Postmodern <[email protected]>
Version bump to 0.1.0.beta1.

19fddc3aeab1833f8a792ec28e87673e9dae2a89 authored about 2 years ago by Postmodern <[email protected]>
Added ruby-3.2 to the CI matrix.

a3cc0be9807802a2705760be3b1a7b949b242d01 authored about 2 years ago by Postmodern <[email protected]>
Add the boilerplate message about being a part of ronin-rb.

6954b8b1ec7e7fa66b41a7012f7234fa8e818861 authored about 2 years ago by Postmodern <[email protected]>
Added `frozen_string_literal: true` comments to all files.

427e025bad400ade71cde3619bb560f9a99aa4d1 authored about 2 years ago by Postmodern <[email protected]>
Added `WebVuln#to_http` (closes #30).

42fbf95e25a27e2fede3ef18c15a82d7c940b37b authored about 2 years ago by Postmodern <[email protected]>
Added `WebVuln#to_curl` (closes #29).

1fd84e7018e086d144b0b238c6aa599732e1bbbb authored about 2 years ago by Postmodern <[email protected]>
Moved `encode_payload` down into `WebVuln`.

ebaff9669ca0912c9ba213eaa7cd6e2153a47d56 authored about 2 years ago by Postmodern <[email protected]>
Fixed YARD type signatures for `WebVuln`.

9f73ed995434405b1b1f90cc2b66a68f26629b8a authored about 2 years ago by Postmodern <[email protected]>
Added `WebVuln::HTTPRequest` (issues #29,#30).

b6a0be24265216bbf4b5f64b0406593b030c6c38 authored about 2 years ago by Postmodern <[email protected]>
Renmaed `CLI::Printing` to `CLI::Logging` and use `log_info` for vulns.

c7eb930cb2ea08fcbbcb619bf9cccc6c9de62643 authored about 2 years ago by Postmodern <[email protected]>
Added a link to Mastodon.

c4c599a73442b358eb0a5744934c935691cf3ec0 authored about 2 years ago by Postmodern <[email protected]>
Removed the Slack link (Discord is better).

ea55ae65268f48dd92b9a1256288e6aae805848f authored about 2 years ago by Postmodern <[email protected]>
Added quotes around the URLs.

747fa1138a1f3f7b6044b00ef8b4aeec73f0e27b authored about 2 years ago by Postmodern <[email protected]>
Added the `ronin-vulns scan` command (closes #19).

50dabc8d193ca3d230add90fa95850d7f6030f22 authored about 2 years ago by Postmodern <[email protected]>
Add a usage to the `--depth` option of `ronin-vulns lfi`.

b84782448cbaff6acae82665815d2630372111ec authored about 2 years ago by Postmodern <[email protected]>
Use `-B` for `--filter-bypass` to not conflict with `-F,--form-param`.

ab8c0d255dffd72adb225bed500434139c06f39d authored about 2 years ago by Postmodern <[email protected]>
Fixed copy/pasted YARDoc.

6228aea836acce23787929f2b60fca03d97e5c0d authored about 2 years ago by Postmodern <[email protected]>
Renamed `--test` to `--test-expr` in the `ronin-vulns ssti` command.

d09d1cfb7c7a270afdfac401fe957437fcc6159a authored about 2 years ago by Postmodern <[email protected]>
Mention documentation and test coverage.

c94a7d186a03bc397da9a5fcf6e4cfec0e76de4d authored about 2 years ago by Postmodern <[email protected]>
Alias `ronin-vulns xss` to `ronin-vulns reflected-xss`.

81b7a97a4d3b12194b6945d97ce311e873227e63 authored about 2 years ago by Postmodern <[email protected]>
Added a Synopsis section.

8f21210ef40516df0a91381d91e39e214cecb926 authored about 2 years ago by Postmodern <[email protected]>