Skip to content

Latest commit

 

History

History
73 lines (53 loc) · 2.65 KB

FAQ.md

File metadata and controls

73 lines (53 loc) · 2.65 KB

FAQ

If you cannot find the answer to your question, either here or in the documentation, feel free to open an issue and use the label "question".

Web interface

Help / Dokuwiki shows "Forbidden"

I cannot access the help pages or the notepad (the Dokuwiki content), and get a "Forbidden" message.

You need to configure your web server to allow access from other hosts on the network to the Dokuwiki content. It is often restricted, by default, to local users only. If you are using Apache, you can look for an ACL like Allow from localhost 127.0.0.1 ::1 and adapt it to your network.

How can I restrict access to IVRE's Web interface

I want to prevent unauthorized access to IVRE's results.

First, you have to configure your web server to authenticate remote users. The most important, of course, is to protect access to CGI files (the static files are publicly available and do not contain any result).

In an AD or Kerberos environment for example, Apache can be configured to provide SSO authentication.

Then, if you want to restrict access to the results based on the user login or domain, you can add the following lines to /etc/ivre.conf:

WEB_DEFAULT_INIT_QUERY = 'noaccess'
WEB_INIT_QUERIES = {
    '[email protected]': 'category:SubNetwork',
    '@ADMIN.NETWORK.AD': 'full',
}

By default, users won't have access to any result. The user [email protected] will have access to the results in the category SubNetwork. The users in the ADMIN.NETWORK.AD realm will have access to all the results.

Can IVRE be used to look for XXX?

IVRE is not a scanner or a network traffic analyzer. It relies on tools like Nmap, Masscan, Bro and p0f, parses their results and stores them in a database.

So when you are asking, for example, "can IVRE scan a network for hosts with the Heartbleed vulnerability?", in reality you are asking two different questions:

  • "Can Nmap or Masscan detect when a scanned hosts is vulnerable to the Heartbleed vulnerability?"
  • "How can IVRE list the hosts that have been found vulnerable to Heartbleed by Nmap or Masscan?"

The first question is not related to IVRE (and should probably be asked to Nmap or Masscan developers), but the second question is (and may be asked as a "question" labeled issue).

For that particular Heartbleed example, both Nmap and Masscan can (reliably) report hosts with the Heartbleed vulnerability, and IVRE can be used to find such hosts.


This file is part of IVRE. Copyright 2011 - 2017 Pierre LALET