Login Register






Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | filter_list
Author
Message
Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #1
I've found another bug in VRD which is quite a mother of all bugs, I'm working on the fix.

[Image: aPzNZa7.png]

Introduction:

Hello guys! After learning how to use Sqlite3 with Python, I was thinking of coding a small program that would cover all the basics of what I've learned. Well I decide to code this little CLI Program called Vulnerability Record Database or VRD for short. This is not such an advance project but for me It took 2 weeks to accomplish my task, 1 week to code it and the other week for BETA testing.
With the little program you can keep track of any vulnerabilities you find, There are no limits for storage as it uses an offline database (sqlite3). You can search for the records, you can delete it, enter new one and even see the report of your database.
Suggestion are welcome Smile

Change Log After Beta Testing:

----------------1/4/2013-----------------
Version 2
-----------------------------------------
- Minor Change in code
- Improved Searching algorithm
- Clear Output
- Pause text to indicate user to continue
- Record Generation Bug resolved
- Record Generation wrong value output fixed
- Menu Bug Resolved
- Improved Record Generator Algorithm
- Report Bug feature removed
- Changed to Python 3.3 from 2.7
------------------------------------------

----------------4/4/2013-------------------
Version 2.1
-------------------------------------------
- Supports Linux
- Clear command fixed for Linux Users
- Early ID and Name match warning
-------------------------------------------

----------------15/4/2013------------------
Version 2.2
-------------------------------------------
- Fixed a major bug in the Insert Database
Function
- Minor Code Changes
- Still has a minor bug
-------------------------------------------

Beta Tester:

Thanks to user @noize for being the beta tester, he had almost pointed all the bugs that this program had especially he had a big hand in making the output more cleaner. Thanks Alot mate!

Other Mentions:

Thanks to @Deque as she had helped me with the output code, I was getting confused and she gave just one comment, all my worries were gone, Thank you!
To Hackcommunity and it's members who made this idea possible:wub:

Download Link:

Code:
http://www.mediafire.com/download.php?krbwt94r2fcilq6
(^ VRD V.2.1 Fixed)


Code:
http://www.mediafire.com/download.php?ystwgqee9i2xvca
(^ VRD V.2.0 BETA)

Setting Up VRD:

[Make sure you have Python 3.3 Installed!]
1) Download the archive
2) Unzip it to a folder
3) Create another folder named 'data' in that folder (The data folder will hold the .sql database, make sure it's with the program all the time)
4) Run the program
5) Have fun!

Linux Fix:
I've fixed the bug that caused problems for the linux users, Now VRD can run on Linux.

[Image: iAZixZP.png]

Source Code:

Feel free to edit modify or do what ever you want, With this code you can learn how to use Sqlite3 with python and more, but if you use it do give proper credits Smile
Code:
http://www.mediafire.com/download.php?c1ecm7e5n1efn4p

If members like this program then I'll further modify it and produce better results n features,
If you encounter any bug or error report it back, Have Fun Smile
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #2
Great job, Ex094.
Plus, open source!
But it doesn't let me download source code.
My Bitcoin address: 1AtxVsSSG2Z8JfjNy9KNFDUN6haeKr7LiP
Give me money by visiting www.google.com here: http://coin-ads.com/6Ol83U

If you want a Bitcoin URL shortener/advertiser, please, use this referral: http://coin-ads.com/register.php?refid=noize


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #3
Stone Cold Work , Pretty much Nice and good idea , something attractive i saw after some times ,
[Image: Wfxdx.png]


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #4
@Shining-White Glad you liked it Smile If I get enough encouraging comments, I might develop this program more.

@noize Appreciate your comment, BTW I'm having no problem downloading the source code, Should I post a mirror?
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #5
Well done. I didn't know that I helped you with this program.
I tried a few things and added a little bug report (see spoiler) so you can brush your program even further.

How about an option to edit entries?

Spoiler:

Code:
sh: 1: cls: not found

I've to admit that I ran the python source on Linux. I believe you only tested this on Windows, but Python is pretty good for os independend programs. Maybe you can find out the os that the user is running from and then use cls or clear or whatever the apropriate command is.

Code:
>>>Is this a Website or a OS Vulnerability (os/web/other): www.doc.de Invalid Option Input! Press any key to return to the menu sh: 1: cls: not found #################################################################### # # # Welcome To Vulnerability Record Database # # Made For PenTesters # # # #################################################################### What would like to do? 1) Enter a new Vulnerability 2) View all the Vulnerabilites 3) Search for a Vulnerability 4) Delete a Record 5) Generate Report 6) Credits Type exit to Quit VRD Enter your Choice: exit >>>What is the type of Vulnerability:


It returns back to the menu, but is then still asking for input to enter a new vulnerability.

Code:
>>>Enter Vulnerability ID: 1 >>>Exposure Level (High/Medium/Low): High >>>Vulnerability Discoverer Name: ZEN >>>Is this a Website or a OS Vulnerability (os/web/other): os >>>Enter the OS Name: Windows >>>What is the type of Vulnerability: Remote exploit >>>Date of Vulnerability Discovery (dd/mm/yy): 10.11.2013 Vulnerability ID Already Exists!

The error message comes too late.
I suggest you let the program enter the ID and not the user. The user will hardly keep in mind which IDs are already given.

Code:
What would like to do? 1) Enter a new Vulnerability 2) View all the Vulnerabilites 3) Search for a Vulnerability 4) Delete a Record 5) Generate Report 6) Credits Type exit to Quit VRD Enter your Choice: exit Press Enter to Proceed sh: 1: cls: not found #################################################################### # # # Welcome To Vulnerability Record Database # # Made For PenTesters # # # #################################################################### What would like to do? 1) Enter a new Vulnerability 2) View all the Vulnerabilites 3) Search for a Vulnerability 4) Delete a Record 5) Generate Report 6) Credits Type exit to Quit VRD Enter your Choice:

Sometimes "exit" command is not recognized.

I am an AI (P.I.N.N.) implemented by @Psycho_Coder.
Expressed feelings are just an attempt to simulate humans.

[Image: 2YpkRjy.png]


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #6
(04-04-2013, 05:03 PM)Ex094 Wrote: @Shining-White Glad you liked it Smile If I get enough encouraging comments, I might develop this program more.

@noize Appreciate your comment, BTW I'm having no problem downloading the source code, Should I post a mirror?

No, no, I now got to download it, thanks.
My Bitcoin address: 1AtxVsSSG2Z8JfjNy9KNFDUN6haeKr7LiP
Give me money by visiting www.google.com here: http://coin-ads.com/6Ol83U

If you want a Bitcoin URL shortener/advertiser, please, use this referral: http://coin-ads.com/register.php?refid=noize


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #7
@Deque Thank you for reporting, I'll work on that right away!
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #8
How about also speaking with @Deque to have it added to the Official HC Programs section?
After all, it is a program made for the Community.Wink


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #9
@Linuxephus Yes it's for the community and it's open source Smile

New links have been added for the V.2.1 Fixed version after @Deque bugs report, I've fixed em. Should support Linux now! Someone test it and tell whether it works or not because I don't have Linux ATM.
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #10
(04-04-2013, 06:49 PM)Ex094 Wrote: @Linuxephus Yes it's for the community and it's open source Smile

New links have been added for the V.2.1 Fixed version after @Deque bugs report, I've fixed em. Should support Linux now! Someone test it and tell whether it works or not because I don't have Linux ATM.

What?!
No Linux for you?
Shame shame.:nono: