yogeshojha / rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
https://yogeshojha.github.io/rengine/
GNU General Public License v3.0
7.52k stars 1.14k forks source link

Feature - Add a way to skip subdomain scan process & use external discovered subdomains lists #89

Closed 0xPrial closed 3 years ago

0xPrial commented 4 years ago

In import target option we can feed multiple domains in txt list . But if you can add a feature where we can skip the Subdomain scanning part and import a subdomains list from external scanned tools as there is many other way to gather Subdomains πŸ˜‡ . Here we can’t skip the Subdomain discovery from scan engine . Hope you will take a look to skip the Subdomain discovery option , so the workflow will be

Cheers

yogeshojha commented 4 years ago

This is in the pipeline @prial261

I am currently working on it. Your suggestions are very much appreciated! Thank you once again

yogeshojha commented 4 years ago

Thanks, @prial261

I have removed the subdomain only scan. Can you please check?

Also, I have added you on contributors.md list as a vote of thanks.

Please continue providing suggestions.

yogeshojha commented 4 years ago

This is fixed, a new issue has been created for URLSCAN.IO, which will be worked on.

0xPrial commented 4 years ago

After you removed the subdomain only scan Now I can skip the subdomain discovery part but now if I import target's subdomain list in a txt file and want to do a scan using following scan engine configuration

Screenshot 2020-07-15 at 10 18 22 PM

Then I need to click on Start scan every subdomain one by one what is not a good idea for such automatic recon tools . Please add a feature so that we can do above configuration scan on all imported subdomain just by one click .

yogeshojha commented 4 years ago

You are absolutely right Prial. But, currently, I am working on couple of other features, I will keep this as a priority and will add the feature soon.

Regala commented 3 years ago

Any luck with this feature to able to import our existing domains? 😬

yogeshojha commented 3 years ago

Yes @Regala, you mean you got targets and then import subdomains, on that target and continue the scan? This is almost over, v0.6 is coming soon, probably this month end with so many enhancements you all have been asking for.

Regala commented 3 years ago

Awesome! πŸ™ πŸ™ πŸ™

yogeshojha commented 3 years ago

I am excited to update you that this is coming :rocket:

This is the flow

  1. Initiate a scan
  2. Choose the scan engine image
  3. Import subdomains from an external source image

If the imported subdomains are not of the domain that you are scanning, they will be ignored.

Regala commented 3 years ago

This looks great @yogeshojha , thank you! Excited to try it out.

(unrelated) quick question since I have you and other people might be interested:

yogeshojha commented 3 years ago

I am excited to release this as well @Regala. Working super hard from past 5 months, and We have so many exciting features coming up, Scan comparision, newly added/removed subdomain/endpoints, ability to find interesting subdomains/endpoints, OSINT, huge improvement in scans, upload custom nuclei patterns, and also now you've GF as well, upload your custom gf pattern and so many exciting features. Closing this soon. Target is June 23, let's see how it goes.

Plus, we do have API, infact everything works in the DRF, I have also worked on the documentation, so I assuee you, this is coming.

Regala commented 3 years ago

Beautiful!!! Great job πŸ’šπŸ’šπŸ’š

yogeshojha commented 3 years ago

This is released. Thanks

yogeshojha commented 3 years ago

https://rengine.wiki/usage/scan_target/#importing-subdomains