Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WebUI and login_script #145

Open
Indigo744 opened this issue Mar 28, 2018 · 2 comments
Open

WebUI and login_script #145

Indigo744 opened this issue Mar 28, 2018 · 2 comments

Comments

@Indigo744
Copy link

Dear dev,

After some research, I've found out the the login_script plugin (and some others) are not supported through the WebUI.

I understand the rationale behind it, as it would be a security issue to let anyone execute script on the host.

However, there are some valid use case: when Arachni WebUI is run and accessed only on localhost.
I think some people are just using the WebUI as a desktop interface on their machine, and not for mounting on a server accessible from the Intranet (or worse, Internet). This is actually how I use Arachni (because I like the WebUI).

As such, activation of these unsafe plugins could be offered through an option (disabled by default obviously) with all the proper security warning message and such.
At run time, a sanity check could be added to verify that the command is coming from localhost and not from elsewhere.

What do you think?

Thanks for your consideration.

@Zapotek
Copy link
Member

Zapotek commented Mar 29, 2018

There are proper ways to do this of course, but unfortunately it won't get done. The WebUI isn't under active development.

@Indigo744
Copy link
Author

That is unfortunate. But I guess you are waiting to finish up on the new engine before reworking the WebUI? User interfaces are time-consuming development...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants