dradis - effective information sharing http://dradis.sourceforge.net/ dradis is an open source tool for sharing information during security assessments. en-gb 7th of March 2010 <h2>dradis v2.5.1 released!</h2> <ul> <li>Improved Note editor: bigger, easier to use and supports formatting!</li> <li>New <strong>First Time User Wizard</strong></li> <li>Keep track of all the activity with the built-in RSS feed</li> <li><strong>Plugin improvements</strong> <ul> <li>New <strong>HTML Export</strong> reporting plugin.</li> <li>New <strong>Burp Upload</strong> plugin so you can use <a href="http://portswigger.net/scanner/">Burp Scanner</a> output.</li> <li>New <strong>Nikto Upload</strong> plugin to use your <a href="http://cirt.net/nikto2">Nikto</a> scan results.</li> </ul> </li> <li>Upgraded libraries: ExtJS 3.1.1, Rails 2.3.5</li> <li>Bugs fixed: #2964273, #2932569, #2963253.</li> </ul> &nbsp; <div class="download"> <a href="download.html">download now</a> </div> dradis team Sun, 07 Mar 2010 20:02:49 +0000 http://dradis.nomejortu.com/announcements.html#07mar10 http://dradis.nomejortu.com/announcements.html#07mar10 5th of February 2010 <h2>dradis v2.5 released!</h2> <ul> <li>Improved Note editor: bigger, easier to use and supports formatting!</li> <li>New <strong>First Time User Wizard</strong></li> <li>Keep track of all the activity with the built-in RSS feed</li> <li><strong>Plugin improvements</strong> <ul> <li>New <strong>HTML Export</strong> reporting plugin.</li> <li>New <strong>Burp Upload</strong> plugin so you can use <a href="http://portswigger.net/scanner/">Burp Scanner</a> output.</li> <li>New <strong>Nikto Upload</strong> plugin to use your <a href="http://cirt.net/nikto2">Nikto</a> scan results.</li> </ul> </li> <li>Upgraded libraries: ExtJS 3.0, Rails 2.3.5</li> <li>Bugs fixed: #2936554, #2938593.</li> </ul> &nbsp; <div class="download"> <a href="download.html">download now</a> </div> dradis team Fri, 05 Feb 2010 12:48:15 +0000 http://dradis.nomejortu.com/announcements.html#05feb10 http://dradis.nomejortu.com/announcements.html#05feb10 31st of October 2009 <h2>dradis v2.4.1 released!</h2> <p>Mainly minor changes and bug fixes:</p> <ul> <li><strong>server</strong>: <ul> <li><strong>Plugin improvements</strong> <ul> <li><strong>Nmap Upload</strong> is now using the <a href="http://rubynmap.sourceforge.net/">Nmap::Parser</a> library.</li> <li>Featuring the new <acronym title="Open Source Vulnerability Database">OSVDB</acronym> Import plugin to query the largest independent and <a href="http://osvdb.org/">open source vulnerability database</a>.</li> </ul> </li> <li><strong>Upload plugins</strong>. Better progress feedback. Improved error condition checking.</li> <li>Note drag'n'drop.</li> <li>New handy Rake tasks: <ul> <li><strong>dradis:reset</strong>: When you are done with your project, use this task to start over. It clears the database and removes the uploaded files.</li> <li><strong>dradis:backup</strong>: If you want to create a backup of your current project, this is the right task for it.</li> </ul> </li> <li>Bugs fixed: #2881746, #2888245, #2889402.</li> </ul> </li> <li><strong>client</strong>: <ul> <li>Bugs fixed: #2888411.</li> </ul> </li> </ul> &nbsp; <div class="download"> <a href="download.html">download now</a> </div> dradis team Sat, 31 Oct 2009 23:08:33 +0000 http://dradis.nomejortu.com/announcements.html#31oct09 http://dradis.nomejortu.com/announcements.html#31oct09 29th of October 2009 <h2>Hacker's Guide to dradis updated</h2> <p>The <a href="hacking.html">Hacker's Guide to dradis</a> has been updated with additional information on how to use our Subversion repository.</p> dradis team Thu, 29 Oct 2009 00:53:49 +0000 http://dradis.nomejortu.com/announcements.html#29oct09 http://dradis.nomejortu.com/announcements.html#29oct09 16th of October 2009 <h2>New Server Plugins</h2> <ul> <li><a href="http://dradisframework.org/community/index.php?topic=16.0">Open Source Vulnerability Database (OSVDB) Import Plugin</a></li> <li><a href="http://dradisframework.org/community/index.php?topic=18.0">Nikto XML output Upload Plugin </a></li> <li><a href="http://dradisframework.org/community/index.php?topic=22.0">Burp Scanner XML Upload Plugin</a></li> </ul> <p>Keep an eye on the <a href="http://dradisframework.org/community/">forums</a> for updates.</p> dradis team Fri, 16 Oct 2009 14:13:44 +0000 http://dradis.nomejortu.com/announcements.html#16oct09 http://dradis.nomejortu.com/announcements.html#16oct09 9th of September 2009 <h2>dradis v2.4 released!</h2> <p>Mainly minor changes and bug fixes:</p> <ul> <li><strong>server</strong>: <ul> <li><strong>Plugin improvements</strong> <ul> <li><strong>Nmap Upload</strong> is now using the <a href="http://rubynmap.sourceforge.net/">Nmap::Parser</a> library.</li> <li>Featuring the new <acronym title="Open Source Vulnerability Database">OSVDB</acronym> Import plugin to query the largest independent and <a href="http://osvdb.org/">open source vulnerability database</a>.</li> </ul> </li> <li><strong>Upload plugins</strong>. Better progress feedback. Improved error condition checking.</li> <li>Note drag'n'drop.</li> <li>New handy Rake tasks: <ul> <li><strong>dradis:reset</strong>: When you are done with your project, use this task to start over. It clears the database and removes the uploaded files.</li> <li><strong>dradis:backup</strong>: If you want to create a backup of your current project, this is the right task for it.</li> </ul> </li> </ul> </li> <li><strong>client</strong>: <ul> <li>Bugs fixed: #2848909.</li> </ul> </li> </ul> &nbsp; <div class="download"> <a href="download.html">download now</a> </div> dradis team Wed, 09 Sep 2009 23:56:05 +0000 http://dradis.nomejortu.com/announcements.html#09sep09 http://dradis.nomejortu.com/announcements.html#09sep09 8th of September 2009 <h2>Import Plugin Tutorial</h2> <p>A new tutorial is avaliable in the <a href="developers.html">Information for Developers</a> page: learn how to create your own <a href="import_plugin.html">Import Plugin</a>.</p> <p>In this tutorial you will learn how to create a <strong>dradis</strong> import plugin to import into the framework's repository information held in external systems.</p> <p>The step-by-step guide shows how to create a plugin that queries the <a href="http://osvdb.org/">Open Source Vulnerability Database</a> (OSVDB) to extract vulnerability information.</p> dradis team Tue, 08 Sep 2009 19:48:59 +0000 http://dradis.nomejortu.com/announcements.html#08sep09 http://dradis.nomejortu.com/announcements.html#08sep09 5th of August 2009 <h2>dradis Framework presented in DEFCON 17</h2> <p>After much anticipation, we presented our framework at <a href="http://defcon.org/html/defcon-17/dc-17-speakers.html#Etd">DEFCON 17</a> in Las Vegas this year.</p> <div class="center"> <img src="/images/defcon17.jpg" width="450" height="338" class="marquee"/> <div>picture by <a href="http://twitter.com/roncharette">@roncharette</a></div> </div> <p>The talk went fine, good attendance and really good feedback and ideas from the attendees. Thanks for coming to see us!</p> <p>The updated set of slides has already been sent to the organisers so they can update the official site. In the mean time:</p> <div class="center"> <object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=defcon172009-08-090806011256-phpapp01&stripped_title=defcon17-dradis-framework-sharing-information-will-get-you-root" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=defcon172009-08-090806011256-phpapp01&stripped_title=defcon17-dradis-framework-sharing-information-will-get-you-root" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object></div> dradis team Wed, 05 Aug 2009 02:33:19 +0000 http://dradis.nomejortu.com/announcements.html#05aug09 http://dradis.nomejortu.com/announcements.html#05aug09 2nd of August 2009 <h2>dradis v2.3 released!</h2> <p>A new release full of <a href="announcements.html#05aug09">DEFCON</a> goodness:</p> <ul> <li><strong>server</strong>: <ul> <li><strong>upload plugins</strong>. A new <a href="server_plugins.html">server plugin</a> category: import into <strong>dradis</strong> the contents of any file (nmap, nessus, etc.).</li> <li>refactor the <strong>WordExport</strong> plugin: <ul> <li>create templates using Word only</li> <li>convert any document into a dradis template in &lt; 10 minutes</li> <li>read more about it the <a href="WordExport_templates.html">WordExport templates</a> tutorial.</li> </ul> </li> <li>project management plugin update: <ul> <li>create project templates for future re-use (read <em>methodologies</em>)</li> <li>export project in .zip format (DB + attachments)</li> <li>import projects/templates</li> <li>checkout / commit project revisions from and to the <strong>Meta-Server</strong> (stay tuned, soon to be released)</li> </ul> </li> <li><strong>email</strong> connector: you can pipe emails into the framework and get your messages (and attachments) added into the repository</li> <li>enhanced nodes tree: filtering and quick actions buttons</li> </ul> </li> <li><strong>client</strong>: <ul> <li>new import extensions: Nessus and Qualys</li> </ul> </li> </ul> &nbsp; <div class="download"> <a href="download.html">download now</a> </div> dradis team Sun, 02 Aug 2009 08:43:21 +0000 http://dradis.nomejortu.com/announcements.html#02aug09 http://dradis.nomejortu.com/announcements.html#02aug09 1st of July 2009 <h2>dradis framework in DEFCON 17</h2> <p>Oh yes! <strong>dradis framework</strong> is going to be in this year's DEFCON. Checkout the <a href="http://defcon.org/html/defcon-17/dc-17-schedule.html">schedule</a> and the talk <a href="http://defcon.org/html/defcon-17/dc-17-speakers.html#Etd">summary</a>.</p> dradis team Wed, 01 Jul 2009 20:40:51 +0000 http://dradis.nomejortu.com/announcements.html#01jul09 http://dradis.nomejortu.com/announcements.html#01jul09 29th of June 2009 <h2>dradis framework in BackTrack 4</h2> <p>The <strong>dradis framework</strong> is now part of BackTrack 4. Checkout the <a href="http://www.remote-exploit.org/backtrack_download.html">Pre Release</a> ISO.</p> <p>Thanks to TheX1le, muts and the rest of the BT team for making this possible.</p> dradis team Mon, 29 Jun 2009 12:57:56 +0000 http://dradis.nomejortu.com/announcements.html#29jun09 http://dradis.nomejortu.com/announcements.html#29jun09 11th of June 2009 <h2>dradis v2.2.0 released!</h2> <p>A new release with some juicy features:</p> <ul> <li><strong>server</strong>: <ul> <li>add attachments to nodes</li> <li><em>refresh</em> buttons to the tree and the notes list</li> <li>force webrick even if mongrel is installed (no SSL support in mongrel)</li> <li>Rails runs in "production" mode</li> </ul> </li> <li><strong>client</strong>: <ul> <li>dradis can be used with wxRuby 2.0.0</li> <li>better error handling for REST web service communication errors</li> <li>easier REST credentials configuration in ./conf/dradis.xml</li> </ul> </li> </ul> <div class="download"> <a href="download.html">download now</a> </div> dradis team Thu, 11 Jun 2009 17:27:26 +0000 http://dradis.nomejortu.com/announcements.html#11jun09 http://dradis.nomejortu.com/announcements.html#11jun09 9th of June 2009 <h2>New flash demo</h2> <p><strong>dradis 2.2</strong> flash demo available <a href="videos/dradis2-02.html">here</a>.</p> dradis team Tue, 09 Jun 2009 19:26:49 +0000 http://dradis.nomejortu.com/announcements.html#09jun09 http://dradis.nomejortu.com/announcements.html#09jun09 3rd of June 2009 <h2>dradis new logo</h2> <p>The project finally has a new logo:</p> <div class="center"> <img src="http://dradis.svn.sourceforge.net/viewvc/dradis/client/trunk/ui/images/logo.png" height="200" width="200" alt="dradis framework logo, inspired in Battlestar Gallactica icons" /> </div> <p>It is the work of <a href="http://www.mrexd.com">Matthew Rex Downham</a> and it is released under a <strong>Creative Commons</strong> <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/us/">Attribution-Noncommercial-Share Alike 3.0</a> license.</p> <p>Ideas about the logo? Comments? Suggestions? Join the conversation at the <a href="http://dradisframework.org/community/index.php?topic=8.0">community forums</a>.</p> dradis team Wed, 03 Jun 2009 03:55:04 +0000 http://dradis.nomejortu.com/announcements.html#03jun09 http://dradis.nomejortu.com/announcements.html#03jun09 17th of April 2009 <h2>dradis v2.1.1 released!</h2> <p>We have a new release with many of the features showcased at <a href="announcements.html#20mar09">dc4420</a>:</p> <ul> <li><strong>server</strong>: <ul> <li>import/export plugin architecture</li> <li>import/export plugin generators</li> <li>sample WordXML export plugin</li> <li>sample WikiMedia import plugin</li> </ul> </li> <li><strong>client</strong>: <ul> <li>import extention allows nmap output imports</li> <li>import note from plain text file</li> <li>more powerful add extension: add a note from the console</li> </ul> </li> </ul> <div class="download"> <a href="download.html">download now</a> </div> dradis team Fri, 17 Apr 2009 21:03:40 +0000 http://dradis.nomejortu.com/announcements.html#17apr09 http://dradis.nomejortu.com/announcements.html#17apr09 4th of April 2009 <h2>dradis community forums</h2> <p><strong>dradis</strong> community <a href="/community/">forums</a> are open!</p> dradis team Sat, 04 Apr 2009 16:01:58 +0000 http://dradis.nomejortu.com/announcements.html#04apr09 http://dradis.nomejortu.com/announcements.html#04apr09 20th of March 2009 <h2>dradis presentation at dc4420</h2> <p><strong>dradis</strong> was presented at the <a href="http://dc4420.org/">Defcon London</a> meeting yesterday. It was good fun and we had lots of valuable feedback. dc4420 - Thanks for the invitation!</p> <p>Here are the slides: <a href="slides/dc4420_2009-03.pdf">dradis - Effective Information Sharing</a>.</p> dradis team Fri, 20 Mar 2009 19:30:21 +0000 http://dradis.nomejortu.com/announcements.html#20mar09 http://dradis.nomejortu.com/announcements.html#20mar09 8th of March 2009 The RSS feed is alive! dradis team Sun, 08 Mar 2009 22:33:09 +0000 http://dradis.nomejortu.com/announcements.html#08mar09 http://dradis.nomejortu.com/announcements.html#08mar09 22nd of February 2009 <h2>dradis v2.0.1 released!</h2> <p>After three weeks, over 60 commits and nearly 1k downloads of <strong>dradis 2.0.0</strong> we have a new release:</p> <ul> <li>Smart command line parsing: the console client accepts multi-word parameters using quote characters</li> <li>The <strong>add</strong> extension brings back the ability to add nodes and categories from the console</li> <li>Close bug <a href="http://sourceforge.net/tracker2/?func=detail&aid=2572271&group_id=209736&atid=1010917">2572271</a>: ruby 1.8.7 compatibility fix for wxWidgets interface</li> <li>First security patch (and a new <a href="security_reports.html">security reports</a> page)</li> <li>Minor bug fixes</li> </ul> <div class="download"> <a href="download.html">download now</a> </div> dradis team Sun, 22 Feb 2009 22:21:15 +0000 http://dradis.nomejortu.com/announcements.html#22feb09 http://dradis.nomejortu.com/announcements.html#22feb09 16th of February 2009 <p>New documentation and how-to guides:</p> <ul> <li>Screencast: <a href="http://www.youtube.com/watch?v=EEHYE3-VWhA">Installing Dradis 2.0 on Backtrack 4.0 Beta</a> (by <em>dyngnosis</em>).</li> <li>Client side extensions: <a href="http://usefulfor.com/ruby/2009/02/17/dradis-extensions-how-they-work-and-how-to-write-them/">Dradis extensions: how they work and how to write them</a></li> <li>How-to export the <strong>dradis</strong> repository to a Word report: <a href="http://usefulfor.com/ruby/2009/02/15/dradis-reporting-quick-neat-word-export/">dradis reporting: quick & neat word export</a></li> </ul> dradis team Mon, 16 Feb 2009 10:12:21 +0000 http://dradis.nomejortu.com/announcements.html#16feb09 http://dradis.nomejortu.com/announcements.html#16feb09 31st of January 2009 <h2>dradis v2.0 released!</h2> <p>After a pre-release in <a href="announcements.html#06aug08">DEFCON-16</a> <strong>dradis 2.0</strong> is out with some awesome new features:-</p> <ul> <li>New <strong>web interface</strong>: <a href="videos/dradis2-01.html">demo</a>.</li> <li>More <strong>flexibility</strong>: the new tree structure makes <strong>dradis</strong> useful for any type of testing.</li> <li>Improved <strong>security</strong>: with SSL support and user authentication.</li> <li><strong>Better integration</strong> with other tools and systems through the new <acronym title="REpresentational State Transfer">REST</acronym> interface.</li> </ul> <p>Read the full <a href="CHANGELOG.html">CHANGELOG</a>. <div class="download"> <a href="download.html">download now</a> </div> <p>&nbsp;</p> dradis team Sat, 31 Jan 2009 23:54:12 +0000 http://dradis.nomejortu.com/announcements.html#31jan09 http://dradis.nomejortu.com/announcements.html#31jan09 11th of November 2008 <p><strong>dradis 2.0</strong> flash demo available <a href="videos/dradis2-01.html">here</a>.</p> dradis team Tue, 11 Nov 2008 23:12:01 +0000 http://dradis.nomejortu.com/announcements.html#11nov08 http://dradis.nomejortu.com/announcements.html#11nov08 6th of August 2008 <p><strong>dradis 2.0</strong> (<em>prerelease-vegas</em>) will be presented at <a href="http://defcon.org/">DEFCON-16</a> as part of john's <a href="http://defcon.org/html/defcon-16/dc-16-speakers.html#Fitzpatrick">Virtually Hacking</a> presentation. New features:</p> <ul> <li>SSL communication between client and server.</li> <li>information is structured using a flexible <em>nodes</em> framework. Check the <a href="screenshots.html">screenshots</a>.</li> <li>the <strong>dradis</strong> Multiverse has arrived.</li> </ul> <p>No official package has been created for this release, you will need to check out the <strong>trunk</strong> (<code>client/trunk/</code> and <code>server/trunk</code>) of the subversion repository at <a href="http://sourceforge.net/svn/?group_id=209736">sourceforge</a>. [browse the <a href="http://dradis.svn.sourceforge.net/viewvc/dradis/">web svn</a>]</p> dradis team Wed, 06 Aug 2008 12:12:34 +0000 http://dradis.nomejortu.com/announcements.html#06aug08 http://dradis.nomejortu.com/announcements.html#06aug08 12th of June 2008 <p>We have created a <a href="download.html#windows">one-click installer</a> for Windows users. It takes care of all the prerequisites and dependencies.</p> dradis team Thu, 12 Jun 2008 14:12:54 +0000 http://dradis.nomejortu.com/announcements.html#12jun08 http://dradis.nomejortu.com/announcements.html#12jun08 4th of April 2008 <h2>dradis v1.2 released!</h2> What is new? <ul> <li><strong>client</strong>: <ul> <li>export to XML module is now part of the standard module set.</li> <li>a new implementation of the command line parser: now it is possible to use single and double quotes to pass multi-word arguments to the different commands.</li> <li>fixed the window.rb:159 bug.</li> </ul> </li> <li><strong>server</strong>: <ul> <li>a slightly less annoying implementation of the web interface <em>auto refresh</em> functionality.</li> <li>the services added through the web interface can have a name now :)</li> <li>simple prevention against embedded XSS.</li> </ul> </li> </ul> dradis team Fri, 04 Apr 2008 16:12:02 +0000 http://dradis.nomejortu.com/announcements.html#04apr08 http://dradis.nomejortu.com/announcements.html#04apr08 29th of February 2008 <h2>dradis v1.1 released!</h2> What is new? <ul> <li>New client GUI that runs in Linux, Windows and Mac OS (<a href="screenshots.html">screenshots</a>).</li> <li>New web interface.</li> <li>Improved step-by-step <a href="install.html">install and setup</a> instructions.</li> <li>New modules (in the <a href="contribute.html">discussion &amp; contribute</a> page): <ul> <li>Export to XML.</li> <li>nmap: run <a href="http://nmap.org/">nmap</a> from <strong>dradis</strong> and store the results in the knowledge base.</li> </ul> </li> </ul> dradis team Fri, 29 Feb 2008 13:10:12 +0000 http://dradis.nomejortu.com/announcements.html#29feb08 http://dradis.nomejortu.com/announcements.html#29feb08