WebScripts: Hardening Audit Report

Links

INTEGRITY

File number: 49 (file should be 0)
Score: 490 (score should be 0)

SCORING

Score Fail Total Compliance (% pourcent)
All 26 2537 98.97516752069373
Critical 0 1358 100.0
High 0 747 100.0
Medium 0 356 100.0
Low 0 6 100.0
Information 26 70 62.857142857142854

FAILED

subjectIDstatelevelseveritycategoryreason
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'view_users.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'view_groups.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'api_view_users.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'api_view_groups.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'get_requests.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'new_password_share.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'download_filename.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'HTML_visible_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'HTML_all_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'HTML_file_history.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'download_all_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'JSON_visible_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'JSON_all_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'JSON_file_history.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'HTML_uploads_properties.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'JSON_uploads_properties.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'log_analysis.py' is not text/plain.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'auth.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'change_my_password.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'add_user.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'get_apikey.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'change_user_password.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'my_user_informations.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'get_password_share.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'new_password_share.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'add_news.py'.

INTEGRITY

FileReasonScoreseverity
static WebScripts.htmlNew sha512 for 'static WebScripts.html' (Old: 01fc45d37a94df5f02f4615ad994642f82518b8bc706d9f976f612460bc33c8ff9d0dc91b73573a70e9b15c127c0d49ce9cb7d787aaf931741b751c1a569343e, New: 4f720ebb276cc4300363c1ddab5529cb67ffc231c5a926c1fdd03d2efabb4910f2ab221bce4642913e0799fb2443c5e3b7d8e33915a387ef188f69664e1ac593)10CRITICAL
static WebScripts.htmlNew sha3_512 for 'static WebScripts.html' (Old: ca1319565d71f5c8e737945e08024a0571d7cc97e2eb576193526a313eb7ba2d58cd740decbe5c1e886617eff545b33ca5ebf82c139ba171090f86ed883e03bb, New: 2eab466197562d8758ebc84ada096dbc766087da384ac06c5d75e3ec7d199baf0a35be0f2a14ff6a2030ec556210b4f09796c166a2203a728d591be5a36c0271)10CRITICAL
static WebScripts.htmlNew modification for 'static WebScripts.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static rss.htmlNew modification for 'static rss.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static cgi.htmlNew modification for 'static cgi.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static Pages.htmlNew modification for 'static Pages.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static manage_defaults_databases.htmlNew modification for 'static manage_defaults_databases.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static uploads_management.htmlNew modification for 'static uploads_management.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static JsonRpc.htmlNew modification for 'static JsonRpc.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static commons.htmlNew sha512 for 'static commons.html' (Old: fcde1d5a884404bf48816a2ad5531a401813a2077d77e117c5d8471043659ccc65ca3f9f8cd8d801cd51db9b7ec8742261c3b258e6f90368579df6883fde846c, New: 5ecb55a7ed3c8989a69982eec337cfda466ab1fdd7582f58dc1b9ca3dfa462611a584f7bc6f1ad2cf1599bb67b5b05f8372807b4430830d02361915c9a8631e0)10CRITICAL
static commons.htmlNew sha3_512 for 'static commons.html' (Old: e751e73c559776dc396ff3412434fb30c5e1ee31756bd1f87d43e3f7cfafc5c98906689a7c57476436b3c77cd375fd51fae6896cf85ddb5e46bedb05613a0274, New: fa8b7263c370e938e84a02255df7c55bdf6bdfc49cc71626c744d4ca65dc06e29b8f939c4c71faba4c1ff549942abce6ca1191e6d852bac8f6aa930d5f869d51)10CRITICAL
static commons.htmlNew modification for 'static commons.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static utils.htmlNew modification for 'static utils.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static Errors.htmlNew modification for 'static Errors.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static index.htmlNew sha512 for 'static index.html' (Old: 5c73d267dca5d4d896c8f90bb3425d3d723f160b54fc74c903ac92fd3da07fbca9631b7a3ee645aae309ac3f004c5fa911e5a93dd248bcbcb8eb619bbbe4db8f, New: eeeafdf77e89f70999ed124dfb2548e173498ae9570ee9e16cd41b51ab026efdd2edb64df812203ab892f1cc00841bfa74a5b93b9e278f7d3d55195c575c7836)10CRITICAL
static index.htmlNew sha3_512 for 'static index.html' (Old: 4e730357a13a827578f367f3f4d135d2b4e467b04affd070a0ca0a501646c7ddd4ff1e65d9c818d060c6aaaeb465ee2179f137bcb124cc95dbabf51294f4f918, New: 64f7559750c52b5af812aa175b9f57edc99f62c017c63562e40fe0b648ca04a8c1af1aa9a6ab91b702ea1ca942f3795ff7f81b6dc0a81ab1db533e9df5b5ba55)10CRITICAL
static index.htmlNew size for 'static index.html' (Old: 23909, New: 23910)10CRITICAL
static index.htmlNew modification for 'static index.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static requests_management.htmlNew modification for 'static requests_management.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static Configurations.htmlNew modification for 'static Configurations.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
static hardening.htmlNew modification for 'static hardening.html' (Old: 2023-02-19 16:44:56, New: 2023-02-20 14:22:34)10CRITICAL
webscript commons.pyNew sha512 for 'webscript commons.py' (Old: 408566bd025060cfe41d9c84d62cf21ff7b5a99785b3d62c6ab8a34e342ceee676c4f9fbc8a1d47f84d43c875711bc78ecc6655a3bd60788d516cff816f35fb9, New: cf46def4950a389ce6153de2e660c5a0af3326a6bb9088d927ca479f9a8a1017e13e59696c7441752cb9ebb6a5672e1d44210fbedb6c3d6598368169ea26e830)10CRITICAL
webscript commons.pyNew sha3_512 for 'webscript commons.py' (Old: 98d5d7eea1ef538fc6446eb4d5def8c4121bc1634d33615e4ae06d8272e7d3eb26052306c46a168f9e8438f7d4227792acc115b325b7388d69f7df13352d7729, New: c470b59fb68c64a8a3ea964fa4630068b26a06ee3dbfef06186b50958f89c2b615f536594395da65bd61319b288f997032dfaddc4f0077da2d64076fed71c625)10CRITICAL
webscript commons.pyNew size for 'webscript commons.py' (Old: 37675, New: 37757)10CRITICAL
webscript commons.pyNew modification for 'webscript commons.py' (Old: 2023-02-03 19:26:58, New: 2023-02-20 14:17:16)10CRITICAL
webscript __init__.pyNew sha512 for 'webscript __init__.py' (Old: 9d98101c6d24a5e6abe57c83749d8757f79555bc82583703e788c07537aab52091b28ec6929f7b84884ae0456d10874de29c55763cd55e3606adc3fdcc64e0c1, New: 2eb978cffbe23fbdef9b5d7323169c85a9053513e9a551e2a5b4a6fdb89ed26ef3d9baf82a9d315a399314fdccc47ce37201134d37a8f6e0c14e4a79ba33fde2)10CRITICAL
webscript __init__.pyNew sha3_512 for 'webscript __init__.py' (Old: dd0489755e8d8c1d8aabf2cb79533c90fab38794c8e6ff0fbf03a1a4a9bf5ac3be7a9bd591883a8a7e3c2648201b48320a715bc3a1bcb04718669c1f5811966d, New: f6fa4603f8cf1d54bbe9451e8460ea67f90b2f6f6f2b8c051fb052f6edd4ad8547df9c8c3ac77013a33fb614cde4113c07949bced57c5149643d4b682aaa78e4)10CRITICAL
webscript __init__.pyNew size for 'webscript __init__.py' (Old: 1845, New: 1846)10CRITICAL
webscript __init__.pyNew modification for 'webscript __init__.py' (Old: 2023-02-19 10:54:28, New: 2023-02-20 14:11:48)10CRITICAL
webscript WebScripts.pyNew sha512 for 'webscript WebScripts.py' (Old: 0eb4831ef758a1fdad57bb4aefc0df59c6f772996f664e599ccf63112798d664ff10ef896f6aa1dddad154088e25fae89ed332ed3b368a692cd873df19d021c6, New: a23012e69728372061013cac72fb7f2cb4ba203245af00734993904506dc024093852f179ccff1a9c4fcc3cb8e6cc34ebae5e19f111c64d5ac085c2cbbb8cc54)10CRITICAL
webscript WebScripts.pyNew sha3_512 for 'webscript WebScripts.py' (Old: 4fed48de58a4b39db936686c50afcf209cabe13a8951440ebe2689e729f5d998465f1bd3ef759da115c18bf693b023373710afbca039dc07f91e549aa0e8a6fc, New: 67fef59ad2d64193556b85bd2078bf1d7f70a6c9a2ce29c2610e48a5ec0ce8ae30095df031b764479dffb072e4ca3a16a5a7eca003e855e8b8d0cf81177d2518)10CRITICAL
webscript WebScripts.pyNew size for 'webscript WebScripts.py' (Old: 69395, New: 69284)10CRITICAL
webscript WebScripts.pyNew modification for 'webscript WebScripts.py' (Old: 2023-02-19 16:43:12, New: 2023-02-20 09:38:58)10CRITICAL
webscript __main__.pyNew sha512 for 'webscript __main__.py' (Old: a32f3a5c5051a85ce5ef8d13830c474d6171c1b5849e023be9bb3e95579df91578f59b3142be7e7f050e46db70c76025fe32a3b07b3df74fe30388b05a604554, New: 8d895528d04448af2c3cdaad634d35ae773a8cfccbb65a9c50074e22bb2c8254caf0b359f933c11abe0efe90acc9abafab618dd9c20a8adf2fb68586d7968abd)10CRITICAL
webscript __main__.pyNew sha3_512 for 'webscript __main__.py' (Old: 818cde736f94ae931b9f9d90e899729350bc555e50b2cc3c0fc4f8e3744e9777bb15371451b2d578ade08fc3def276fcc050d9fa47a36bef470ea5cb267474e3, New: 7f86b95038f431203795a1f60f152623bdab712b825f3d9147d6f693fa05c688c45c7a1d8596a1d2460be06678c66bba8f761483dda7d79db1087a9c777b7585)10CRITICAL
webscript __main__.pyNew modification for 'webscript __main__.py' (Old: 2023-02-19 10:53:34, New: 2023-02-19 14:00:36)10CRITICAL
server configuration server.jsonNew modification for 'server configuration server.json' (Old: 2023-02-19 11:14:26, New: 2023-02-20 12:29:26)10CRITICAL
script configuration change_my_password.jsonNew modification for 'script configuration change_my_password.json' (Old: 2023-02-19 11:14:26, New: 2023-02-20 12:29:26)10CRITICAL
script configuration default_admin_scripts.jsonNew modification for 'script configuration default_admin_scripts.json' (Old: 2023-02-19 11:14:26, New: 2023-02-20 12:29:26)10CRITICAL
script configuration default_requests_scripts.jsonNew modification for 'script configuration default_requests_scripts.json' (Old: 2023-02-19 11:14:26, New: 2023-02-20 12:29:26)10CRITICAL
script configuration default_password_scripts.jsonNew modification for 'script configuration default_password_scripts.json' (Old: 2023-02-19 11:14:26, New: 2023-02-20 12:29:26)10CRITICAL
script configuration default_uploads_scripts.jsonNew modification for 'script configuration default_uploads_scripts.json' (Old: 2023-02-19 11:14:26, New: 2023-02-20 12:29:26)10CRITICAL
script configuration default_rss_scripts.jsonNew modification for 'script configuration default_rss_scripts.json' (Old: 2023-02-19 11:14:26, New: 2023-02-20 12:29:26)10CRITICAL
script configuration default_log_scripts.jsonNew modification for 'script configuration default_log_scripts.json' (Old: 2023-02-19 11:14:26, New: 2023-02-20 12:29:26)10CRITICAL
venv scripts/bin WebScriptsNew sha512 for 'venv scripts/bin WebScripts' (Old: 991b19f29a7dbaac166092b7d0ebd39af856dd8ee74de3cdb5261f8405a867498326e6c3d727ba2e4ce5394202806242b5035ae752009c7af978ff56c3372247, New: 7cc0e4a2c1e3c46565148a92ba660716a857b97e4af730bc8112c4816302d079966adf5bf136fbcc4e77d7a786384d8e733afb5d993247c649b0c85cbaad3242)10CRITICAL
venv scripts/bin WebScriptsNew sha3_512 for 'venv scripts/bin WebScripts' (Old: 8fde14117fbb27fa188e01295ac87a8d2e437b9467a9c9b73968bd24b2fa53d2176a3e5f43d8fc31042b56a48adcd58400457d941fb7f0aa83b814430bbc097c, New: 05945a048523935cf98ceee9bccba032ebecfe44a596eff379bdead0e3bb2717f4f01ec7c52246402061862db9bc0e5d883a5cf2e552b755cce0d158e5829c05)10CRITICAL
venv scripts/bin WebScriptsNew size for 'venv scripts/bin WebScripts' (Old: 999, New: 1002)10CRITICAL
venv scripts/bin WebScriptsNew modification for 'venv scripts/bin WebScripts' (Old: 2023-02-19 11:14:20, New: 2023-02-20 12:29:14)10CRITICAL
venv scripts/bin wsgi.pyNew modification for 'venv scripts/bin wsgi.py' (Old: 2023-02-19 11:14:20, New: 2023-02-20 12:29:14)10CRITICAL

CRITICAL

subjectIDstatelevelseveritycategoryreason
Network Interface2PASS9CRITICALConfigurationServer interface is not 127.0.0.1.
System user1PASS9CRITICALProcessWebScripts is launch with admin rights.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config/server.json'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config/loggers.ini'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/auth.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/py/show_license.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/change_my_password.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/add_user.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/add_group.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/view_users.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/get_apikey.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/api_view_groups.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/delete_user.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/delete_group.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/api_view_users.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/api_view_groups.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/change_user_password.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/account/my_user_informations.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/request/get_request.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/request/get_requests.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/request/delete_request.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/passwords/password_generator.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/passwords/get_password_share.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/passwords/new_password_share.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/upload_file.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/delete_file.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/download_filename.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/HTML_visible_files.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/HTML_all_files.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/HTML_file_history.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/download_all_files.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/JSON_visible_files.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/JSON_all_files.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/JSON_file_history.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/HTML_uploads_properties.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/uploads/JSON_uploads_properties.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/rss/add_news.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/logs/log_viewer.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/scripts/logs/log_analysis.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/modules/error_pages.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/modules/share.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/modules/cgi.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/modules/rss.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/modules/JsonRpc.py'.
File owner11PASS10CRITICALFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/modules/notification.py'.
Directory owner33PASS10CRITICALFilesDirectory owner for '/home/kali/Documents/WebScripts' is not root.
Directory permissions34PASS10CRITICALFilesDirectory permissions for '/home/kali/Documents/WebScripts' is not 755 (drwxr-xr-x).
Directory owner33PASS10CRITICALFilesDirectory owner for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config/scripts' is not root.
Directory permissions34PASS10CRITICALFilesDirectory permissions for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config/scripts' is not 755 (drwxr-xr-x).
Directory owner33PASS10CRITICALFilesDirectory owner for '/home/kali/Documents/WebScripts/bin' is not root.
Directory permissions34PASS10CRITICALFilesDirectory permissions for '/home/kali/Documents/WebScripts/bin' is not 755 (drwxr-xr-x).
Directory owner33PASS10CRITICALFilesDirectory owner for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config/files' is not root.
Directory permissions34PASS10CRITICALFilesDirectory permissions for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config/files' is not 755 (drwxr-xr-x).
Directory owner33PASS10CRITICALFilesDirectory owner for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config' is not root.
Directory permissions34PASS10CRITICALFilesDirectory permissions for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config' is not 755 (drwxr-xr-x).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'server.json' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'loggers.ini' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_index_js_scripts.js' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_js_scripts.js' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_script_js_scripts.js' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'notification.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'rss.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'cgi.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'Pages.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'manage_defaults_databases.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'uploads_management.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'csp.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'get_request.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'JsonRpc.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'commons.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'utils.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'Errors.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'index.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'requests_management.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'Configurations.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'share.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for '__init__.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'hardening.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'error_pages.html' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_index_style.css' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_style.css' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_script_style.css' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_header.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts1.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts3.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts5.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_icon.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts4.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts2.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts7.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts6.png' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_header.jpg' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'webscripts_icon.jpg' is not 400 (r-- --- ---).
File permissions (r--)12PASS10CRITICALFilesFile rights for 'WebScripts.pdf' is not 400 (r-- --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'auth.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'show_license.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'change_my_password.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'add_user.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'add_group.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'view_users.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'get_apikey.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'api_view_groups.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'delete_user.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'delete_group.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'api_view_users.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'api_view_groups.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'change_user_password.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'my_user_informations.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'get_request.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'get_requests.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'delete_request.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'password_generator.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'get_password_share.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'new_password_share.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'upload_file.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'delete_file.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'download_filename.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'HTML_visible_files.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'HTML_all_files.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'HTML_file_history.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'download_all_files.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'JSON_visible_files.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'JSON_all_files.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'JSON_file_history.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'HTML_uploads_properties.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'JSON_uploads_properties.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'add_news.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'log_viewer.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'log_analysis.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'error_pages.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'share.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'cgi.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'rss.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'JsonRpc.py' is not 0 for group and 0 for other (r-x --- ---).
File permissions (r-x)12PASS10CRITICALFilesFile rights for 'notification.py' is not 0 for group and 0 for other (r-x --- ---).

HIGH

subjectIDstatelevelseveritycategoryreason
Active authentication15PASS7HIGHConfigurationAuthentication is disabled.
Default credentials11PASS7HIGHPasswordAdmin password is Admin.
Blacklist configuration5PASS7HIGHConfigurationBlacklist is not configured.
Debug mode4PASS6HIGHConfigurationDebug configuration is not False.
Security configuration3PASS6HIGHConfigurationSecurity configuration is not True.
SMTP password protection6PASS7HIGHConfigurationSMTP password is not protected.
WebProxy number36PASS7HIGHConfigurationWebProxy number is not defined.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'auth.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'show_license.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'change_my_password.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'add_user.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'add_group.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'view_users.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'get_apikey.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'view_groups.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'delete_user.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'delete_group.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'api_view_users.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'api_view_groups.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'change_user_password.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'my_user_informations.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'get_request.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'get_requests.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'delete_request.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'password_generator.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'get_password_share.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'new_password_share.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'upload_file.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'delete_file.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'download_filename.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'HTML_visible_files.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'HTML_all_files.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'HTML_file_history.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'download_all_files.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'JSON_visible_files.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'JSON_all_files.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'JSON_file_history.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'HTML_uploads_properties.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'JSON_uploads_properties.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'add_news.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'log_viewer.py' launcher is not defined in configuration files or is not absolute.
Script launcher18PASS7HIGHScript ConfigurationThe path of 'log_analysis.py' launcher is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'auth.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'show_license.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'change_my_password.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'add_user.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'add_group.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'view_users.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'get_apikey.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'view_groups.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'delete_user.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'delete_group.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'api_view_users.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'api_view_groups.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'change_user_password.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'my_user_informations.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'get_request.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'get_requests.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'delete_request.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'password_generator.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'get_password_share.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'new_password_share.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'upload_file.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'delete_file.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'download_filename.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'HTML_visible_files.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'HTML_all_files.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'HTML_file_history.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'download_all_files.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'JSON_visible_files.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'JSON_all_files.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'JSON_file_history.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'HTML_uploads_properties.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'JSON_uploads_properties.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'add_news.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'log_viewer.py' is not defined in configuration files or is not absolute.
Script path17PASS7HIGHScript ConfigurationThe path of 'log_analysis.py' is not defined in configuration files or is not absolute.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'auth.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'show_license.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'change_my_password.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'add_user.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'add_group.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'view_users.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'get_apikey.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'view_groups.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'delete_user.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'delete_group.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'api_view_users.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'api_view_groups.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'change_user_password.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'my_user_informations.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'get_request.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'get_requests.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'delete_request.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'password_generator.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'get_password_share.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'new_password_share.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'upload_file.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'delete_file.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'download_filename.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'HTML_visible_files.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'HTML_all_files.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'HTML_file_history.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'download_all_files.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'JSON_visible_files.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'JSON_all_files.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'JSON_file_history.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'HTML_uploads_properties.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'JSON_uploads_properties.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'add_news.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'log_viewer.py' is not text/plain.
Error content type9PASS6HIGHScript ConfigurationThe content type of the stderr for 'log_analysis.py' is not text/plain.

MEDIUM

subjectIDstatelevelseveritycategoryreason
Configurations files31PASS5MEDIUMInstallationWebScripts should be configured by only one configuration file (1 found: /home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/config/server.json).
Export file13PASS4MEDIUMFilesThe export configuration file exist, should be deleted on production.
Force authentication14PASS5MEDIUMConfigurationAuthentication is not forced.
Authentication exclusions16PASS5MEDIUMConfigurationAuthentication exclusions is not restricted.
Log level7PASS5MEDIUMConfigurationLog level is not 0.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/js/webscripts_index_js_scripts.js'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/js/webscripts_js_scripts.js'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/js/webscripts_script_js_scripts.js'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/WebScripts.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/notification.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/rss.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/cgi.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/Pages.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/manage_defaults_databases.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/uploads_management.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/csp.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/get_request.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/JsonRpc.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/commons.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/utils.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/Errors.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/index.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/requests_management.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/Configurations.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/share.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/__init__.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/hardening.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/html/error_pages.html'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/css/webscripts_index_style.css'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/css/webscripts_style.css'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/css/webscripts_script_style.css'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/webscripts_header.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/WebScripts1.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/WebScripts3.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/WebScripts5.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/webscripts_icon.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/WebScripts4.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/WebScripts2.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/WebScripts7.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/WebScripts6.png'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/webscripts_header.jpg'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/images/webscripts_icon.jpg'.
File owner11PASS4MEDIUMFilesFile owner is not 'kali' for '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/static/pdf/WebScripts.pdf'.
Module path30PASS5MEDIUMConfigurationModule path '/home/kali/Documents/WebScripts/lib/python3.10/site-packages/WebScripts/modules' is not absolute.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'auth.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'show_license.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'change_my_password.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'add_user.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'add_group.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'view_users.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'get_apikey.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'view_groups.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'delete_user.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'delete_group.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'api_view_users.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'api_view_groups.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'change_user_password.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'my_user_informations.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'get_request.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'get_requests.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'delete_request.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'password_generator.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'get_password_share.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'new_password_share.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'upload_file.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'delete_file.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'download_filename.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'HTML_visible_files.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'HTML_all_files.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'HTML_file_history.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'download_all_files.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'JSON_visible_files.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'JSON_all_files.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'JSON_file_history.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'HTML_uploads_properties.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'JSON_uploads_properties.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'add_news.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'log_viewer.py' timeout is not defined.
Script timeout35PASS5MEDIUMScript ConfigurationThe 'log_analysis.py' timeout is not defined.

LOW

subjectIDstatelevelseveritycategoryreason
Virtualenv0PASS3LOWInstallationWebScripts is not install in virtualenv.
Virtualenv modules32PASS3LOWInstallationWebScripts should be install in empty virtualenv (except WebScriptsTools), modules found: .

INFORMATION

subjectIDstatelevelseveritycategoryreason
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'auth.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'show_license.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'change_my_password.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'add_user.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'add_group.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'view_users.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'get_apikey.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'view_groups.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'delete_user.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'delete_group.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'api_view_users.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'api_view_groups.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'change_user_password.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'my_user_informations.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'get_request.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'get_requests.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'delete_request.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'password_generator.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'get_password_share.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'new_password_share.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'upload_file.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'delete_file.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'download_filename.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'HTML_visible_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'HTML_all_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'HTML_file_history.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'download_all_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'JSON_visible_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'JSON_all_files.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'JSON_file_history.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'HTML_uploads_properties.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'JSON_uploads_properties.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'add_news.py' is not text/plain.
Output content type10PASS1INFORMATIONScript ConfigurationThe content type of the script named 'log_viewer.py' is not text/plain.
Output content type10FAIL1INFORMATIONScript ConfigurationThe content type of the script named 'log_analysis.py' is not text/plain.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'auth.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'show_license.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'change_my_password.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'add_user.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'add_group.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'view_users.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'get_apikey.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'view_groups.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'delete_user.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'delete_group.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'api_view_users.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'api_view_groups.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'change_user_password.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'my_user_informations.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'get_request.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'get_requests.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'delete_request.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'password_generator.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'get_password_share.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'new_password_share.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'upload_file.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'delete_file.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'download_filename.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'HTML_visible_files.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'HTML_all_files.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'HTML_file_history.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'download_all_files.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'JSON_visible_files.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'JSON_all_files.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'JSON_file_history.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'HTML_uploads_properties.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'JSON_uploads_properties.py'.
Command log8FAIL1INFORMATIONScript ConfigurationScript command is not logged for 'add_news.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'log_viewer.py'.
Command log8PASS1INFORMATIONScript ConfigurationScript command is not logged for 'log_analysis.py'.