google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

PRP: Request Web Application Fingerprint - Grafana #392

Open W0ngL1 opened 4 months ago

W0ngL1 commented 4 months ago

Hi there,

I would like to start the implementation for a web application fingerprint that detects the following software - Grafana.

Docker hub image: https://hub.docker.com/r/grafana/grafana

Please let me know if this is in scope.

tooryx commented 4 months ago

Hi @W0ngL1,

We already have an issue open for Kibana: https://github.com/google/tsunami-security-scanner-plugins/issues/134 Please track directly on that other issue if the original author does not intend to continue development.

~tooryx

W0ngL1 commented 4 months ago

Hi @tooryx, Grafana is not the same project or sub project of Kibana, so I wonder why they can be related.

tooryx commented 4 months ago

Oops, my bad. I will add it to your queue and will let you know when we review this issue if you can start development.

tooryx commented 4 months ago

We already have Grafana fingerprints. But it seems like the fingerprints are a bit old and we do not have the update script. I will check with the rest of the team if we want to have an external contribution for this.

I will keep you updated. ~tooryx

W0ngL1 commented 4 months ago

Copy that. Please let me know if the team need a PR.