Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bug: Vulnerabilities Discovered 0 #1365

Open
1 task done
zinwelzl opened this issue Aug 11, 2024 · 9 comments
Open
1 task done

bug: Vulnerabilities Discovered 0 #1365

zinwelzl opened this issue Aug 11, 2024 · 9 comments
Labels
bug Something isn't working top-priority

Comments

@zinwelzl
Copy link

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

Test URL with lot of vulns, rengine 2.1.2. last update, Vulnerabilities Discovered 0.

All work great, but after today update, no vulns discovered.

Expected Behavior

Vulnerabilities Discovered should have vulns, this is my test site.

Steps To Reproduce

Full scan

Environment

- reNgine: 2.1.2

last update

Anything else?

No response

@zinwelzl zinwelzl added the bug Something isn't working label Aug 11, 2024
Copy link
Contributor

👋 Hi @zinwelzl,
Issues is only for reporting a bug/feature request. Please read documentation before raising an issue https://rengine.wiki
For very limited support, questions, and discussions, please join reNgine Discord channel: https://discord.gg/azv6fzhNCE
Please include all the requested and relevant information when opening a bug report. Improper reports will be closed without any response.

@zinwelzl
Copy link
Author

ZAP and others tools find more then 50 vulns, even there is more, but regine after update 0 vulns.

@zinwelzl
Copy link
Author

https://ginandjuice.shop/ also no vulns with rengine, other tools find vuls

@lintianyuan666
Copy link

I found this bug too.No vulns found whit rengine,and no subdomain found too.

@jimmyn88
Copy link

Has anyone solved the problem?

@yogeshojha
Copy link
Owner

@lintianyuan666 no subdomains? which tools are you using in yaml for subdomain enum?

@lintianyuan666
Copy link

@lintianyuan666 no subdomains? which tools are you using in yaml for subdomain enum?

default tools.proberly subfinder

@jimmyn88
Copy link

jimmyn88 commented Sep 24, 2024

Anyway, manually running Nuclei with the same command as reNgine, but replacing /usr/src/scan_results/juice-shop.herokuapp.com_10/urls_unfurled.txt with the URL (juice-shop.herokuapp.com), it successfully returns vulnerabilities. The issue seems to be that the urls_unfurled.txt file is empty.

@jimmyn88
Copy link

jimmyn88 commented Oct 5, 2024

Can I ask how the file urls_unfurled.txt is generated? Which method does the platform use to make it?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working top-priority
Projects
None yet
Development

No branches or pull requests

4 participants