René's URL Explorer Experiment


Title: Add a typo3 security vulnerability scanner · Issue #568 · secureCodeBox/secureCodeBox · GitHub

Open Graph Title: Add a typo3 security vulnerability scanner · Issue #568 · secureCodeBox/secureCodeBox

X Title: Add a typo3 security vulnerability scanner · Issue #568 · secureCodeBox/secureCodeBox

Description: 🚓 New Scanner implementation request Is your feature request related to a problem As a security analyst i would like to use the secureCodeBox to check my external attack surface. Especially CMS systems like Wordpress or Typo3 are common ...

Open Graph Description: 🚓 New Scanner implementation request Is your feature request related to a problem As a security analyst i would like to use the secureCodeBox to check my external attack surface. Especially CMS sys...

X Description: 🚓 New Scanner implementation request Is your feature request related to a problem As a security analyst i would like to use the secureCodeBox to check my external attack surface. Especially CMS sys...

Opengraph URL: https://github.com/secureCodeBox/secureCodeBox/issues/568

X: @github

direct link

Domain: github.com


Hey, it has json ld scripts:
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Add a typo3 security vulnerability scanner","articleBody":"## 🚓  New Scanner implementation request\r\n\u003c!--\r\nThank you for contributing to our project 🙌\r\n\r\nBefore opening a new issue, please make sure that we do not have any duplicates already open. You can ensure this by searching the issue list for this repository. If there is a duplicate, please close your issue and add a comment to the existing issue instead. Also, please, have a look at our FAQs and existing questions before opening a new question.\r\n--\u003e\r\n\r\n### Is your feature request related to a problem\r\n\u003c!-- Please describe a clear and concise description of what the problem is. \r\n     Use commmon user story patterns like https://en.wikipedia.org/wiki/User_story:\r\n      - As a \u003crole\u003e I can \u003ccapability\u003e, so that \u003creceive benefit\u003e\r\n      - In order to \u003creceive benefit\u003e as a \u003crole\u003e, I can \u003cgoal/desire\u003e\r\n      - As \u003cwho\u003e \u003cwhen\u003e \u003cwhere\u003e, I \u003cwant\u003e because \u003cwhy\u003e\r\n     For example... As a secureCodeBox user i'm always frustrated when [...] --\u003e\r\nAs a security analyst i would like to use the secureCodeBox to check my external attack surface. Especially CMS systems like Wordpress or Typo3 are common systems that may introduce new vulnerabilites on a regular basis. \r\n\r\nThe BlogPost of @JavanXD https://javan.de/securing-typo3-cms-new-security-scanner/ also motivates this topic.\r\n\r\n### Describe the solution you'd like\r\n\u003c!-- A clear and concise description of what you want to happen. --\u003e\r\nSince the secureCodeBox already supports the Wordpress scanner WPScan it would be great to also add at least one Typo3 scanner. There are two candidates (referring to the blog post):\r\n- https://github.com/JavanXD/Typo3AccessChecker – Check if Typo3 security guidelines are followed.\r\n- https://github.com/whoot/Typo3Scan – Typo3 Enumerator: Enumerates extensions to gain information about outdated and \r\n\r\n### Describe alternatives you've considered\r\n\u003c!-- A clear and concise description of any alternative solutions or features you've considered. --\u003e\r\n\r\n### Additional context\r\n\u003c!-- Add any other context or screenshots about the feature request here. --\u003e\r\n- https://javan.de/securing-typo3-cms-new-security-scanner/\r\n- https://github.com/JavanXD/Typo3AccessChecker – Check if Typo3 security guidelines are followed.\r\n- https://github.com/whoot/Typo3Scan – Typo3 Enumerator: Enumerates extensions to gain information about outdated and vulnerable extensions.\r\n\r\n## Steps to implement a new scanner\r\nHint: A general guide how to implement a new SCB scanner is documented [here](https://docs.securecodebox.io/docs/contributing/integrating-a-scanner)\r\n\r\n- [x] Create a new folder with the name of the [scanner here](https://github.com/secureCodeBox/secureCodeBox/tree/master/scanners)\r\n- [x] Add a `README.gotmpl` and give a [brief overview](https://docs.securecodebox.io/docs/contributing/integrating-a-scanner/readme) of the scanner and its configuration options.\r\n- [x] Add a HelmChart and document all configuration options.\r\n- [x] Implement a new scanner specific `scan-type.yaml`\r\n- [x] Implement a new scanner specific `parse-definition.yaml`\r\n- [x] Add (optional) some `cascading-rules.yaml` like documented [here](https://docs.securecodebox.io/docs/api/crds/cascading-rule)\r\n- [x] Add (optional) a `Dockerfile` for the scanner if there is no existing one publicly available on dockerHub\r\n- [x] Use the [parser-SDK](https://github.com/secureCodeBox/secureCodeBox/tree/master/parser-sdk) to implement a new findings parser (currently based on NodeJS)\r\n- [x] Add unit tests with at minimum 80% test coverage\r\n- [x] Add some example `scan.yaml` and `finding.yaml` files in the [example folder](https://docs.securecodebox.io/docs/contributing/integrating-a-scanner/examples-dir)\r\n- [x] Implement a [new integration or E2E test](https://docs.securecodebox.io/docs/contributing/integrating-a-scanner/integration-tests) for the hook [here](https://github.com/secureCodeBox/secureCodeBox/tree/master/tests/integration)\r\n","author":{"url":"https://github.com/rfelber","@type":"Person","name":"rfelber"},"datePublished":"2021-07-30T11:06:36.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":1},"url":"https://github.com/568/secureCodeBox/issues/568"}

route-pattern/_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format)
route-controllervoltron_issues_fragments
route-actionissue_layout
fetch-noncev2:2362bf98-ab90-4fef-fc25-69c0250e8594
current-catalog-service-hash81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114
request-id8698:210A73:AD6908:EA28A8:69785C92
html-safe-nonce9eed38e38b8a563fb334fc818619d67ef6431d72beadaa787cb601b97cfc6e03
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4Njk4OjIxMEE3MzpBRDY5MDg6RUEyOEE4OjY5Nzg1QzkyIiwidmlzaXRvcl9pZCI6IjM3Mzg2OTU0MzAwODI5NDQxNDYiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ==
visitor-hmac6af782b7d2fe3b33033aa182ccf758b5bbfd48a8e1a4f16f44cd14078be36fc2
hovercard-subject-tagissue:956645747
github-keyboard-shortcutsrepository,issues,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///voltron/issues_fragments/issue_layout
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/secureCodeBox/secureCodeBox/568/issue_layout
twitter:imagehttps://opengraph.githubassets.com/166eae80227719a5d33589cb2e80492f8e0f917190e33c6af9f7f82518891dad/secureCodeBox/secureCodeBox/issues/568
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/166eae80227719a5d33589cb2e80492f8e0f917190e33c6af9f7f82518891dad/secureCodeBox/secureCodeBox/issues/568
og:image:alt🚓 New Scanner implementation request Is your feature request related to a problem As a security analyst i would like to use the secureCodeBox to check my external attack surface. Especially CMS sys...
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
og:author:usernamerfelber
hostnamegithub.com
expected-hostnamegithub.com
None2981c597c945c1d90ac6fa355ce7929b2f413dfe7872ca5c435ee53a24a1de50
turbo-cache-controlno-preview
go-importgithub.com/secureCodeBox/secureCodeBox git https://github.com/secureCodeBox/secureCodeBox.git
octolytics-dimension-user_id34573705
octolytics-dimension-user_loginsecureCodeBox
octolytics-dimension-repository_id80711933
octolytics-dimension-repository_nwosecureCodeBox/secureCodeBox
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id80711933
octolytics-dimension-repository_network_root_nwosecureCodeBox/secureCodeBox
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release520b65a872113b919c1bbdb03834a50af15859fd
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/secureCodeBox/secureCodeBox/issues/568#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FsecureCodeBox%2FsecureCodeBox%2Fissues%2F568
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FsecureCodeBox%2FsecureCodeBox%2Fissues%2F568
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fissues_fragments%2Fissue_layout&source=header-repo&source_repo=secureCodeBox%2FsecureCodeBox
Reloadhttps://github.com/secureCodeBox/secureCodeBox/issues/568
Reloadhttps://github.com/secureCodeBox/secureCodeBox/issues/568
Reloadhttps://github.com/secureCodeBox/secureCodeBox/issues/568
secureCodeBox https://github.com/secureCodeBox
secureCodeBoxhttps://github.com/secureCodeBox/secureCodeBox
Notifications https://github.com/login?return_to=%2FsecureCodeBox%2FsecureCodeBox
Fork 177 https://github.com/login?return_to=%2FsecureCodeBox%2FsecureCodeBox
Star 950 https://github.com/login?return_to=%2FsecureCodeBox%2FsecureCodeBox
Code https://github.com/secureCodeBox/secureCodeBox
Issues 72 https://github.com/secureCodeBox/secureCodeBox/issues
Pull requests 3 https://github.com/secureCodeBox/secureCodeBox/pulls
Discussions https://github.com/secureCodeBox/secureCodeBox/discussions
Actions https://github.com/secureCodeBox/secureCodeBox/actions
Projects 1 https://github.com/secureCodeBox/secureCodeBox/projects
Security 1 https://github.com/secureCodeBox/secureCodeBox/security
Insights https://github.com/secureCodeBox/secureCodeBox/pulse
Code https://github.com/secureCodeBox/secureCodeBox
Issues https://github.com/secureCodeBox/secureCodeBox/issues
Pull requests https://github.com/secureCodeBox/secureCodeBox/pulls
Discussions https://github.com/secureCodeBox/secureCodeBox/discussions
Actions https://github.com/secureCodeBox/secureCodeBox/actions
Projects https://github.com/secureCodeBox/secureCodeBox/projects
Security https://github.com/secureCodeBox/secureCodeBox/security
Insights https://github.com/secureCodeBox/secureCodeBox/pulse
New issuehttps://github.com/login?return_to=https://github.com/secureCodeBox/secureCodeBox/issues/568
New issuehttps://github.com/login?return_to=https://github.com/secureCodeBox/secureCodeBox/issues/568
Add a typo3 security vulnerability scannerhttps://github.com/secureCodeBox/secureCodeBox/issues/568#top
https://github.com/Ilyesbdlala
good first issueGood for newcomershttps://github.com/secureCodeBox/secureCodeBox/issues?q=state%3Aopen%20label%3A%22good%20first%20issue%22
scannerImplement or update a security scannerhttps://github.com/secureCodeBox/secureCodeBox/issues?q=state%3Aopen%20label%3A%22scanner%22
v3.1.0https://github.com/secureCodeBox/secureCodeBox/milestone/10
https://github.com/rfelber
https://github.com/rfelber
rfelberhttps://github.com/rfelber
on Jul 30, 2021https://github.com/secureCodeBox/secureCodeBox/issues/568#issue-956645747
@JavanXDhttps://github.com/JavanXD
https://javan.de/securing-typo3-cms-new-security-scanner/https://javan.de/securing-typo3-cms-new-security-scanner/
https://github.com/JavanXD/Typo3AccessCheckerhttps://github.com/JavanXD/Typo3AccessChecker
https://github.com/whoot/Typo3Scanhttps://github.com/whoot/Typo3Scan
https://javan.de/securing-typo3-cms-new-security-scanner/https://javan.de/securing-typo3-cms-new-security-scanner/
https://github.com/JavanXD/Typo3AccessCheckerhttps://github.com/JavanXD/Typo3AccessChecker
https://github.com/whoot/Typo3Scanhttps://github.com/whoot/Typo3Scan
herehttps://docs.securecodebox.io/docs/contributing/integrating-a-scanner
scanner herehttps://github.com/secureCodeBox/secureCodeBox/tree/master/scanners
brief overviewhttps://docs.securecodebox.io/docs/contributing/integrating-a-scanner/readme
herehttps://docs.securecodebox.io/docs/api/crds/cascading-rule
parser-SDKhttps://github.com/secureCodeBox/secureCodeBox/tree/master/parser-sdk
example folderhttps://docs.securecodebox.io/docs/contributing/integrating-a-scanner/examples-dir
new integration or E2E testhttps://docs.securecodebox.io/docs/contributing/integrating-a-scanner/integration-tests
herehttps://github.com/secureCodeBox/secureCodeBox/tree/master/tests/integration
Ilyesbdlalahttps://github.com/Ilyesbdlala
good first issueGood for newcomershttps://github.com/secureCodeBox/secureCodeBox/issues?q=state%3Aopen%20label%3A%22good%20first%20issue%22
scannerImplement or update a security scannerhttps://github.com/secureCodeBox/secureCodeBox/issues?q=state%3Aopen%20label%3A%22scanner%22
v3.1.0https://github.com/secureCodeBox/secureCodeBox/milestone/10
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.