From 781918782f373cf728dae36bcc79329afda09b65 Mon Sep 17 00:00:00 2001 From: doomedraven Date: Tue, 8 Sep 2026 08:57:08 +0200 Subject: [PATCH 1/5] Update reporthtml.py (#3215) --- modules/reporting/reporthtml.py | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/modules/reporting/reporthtml.py b/modules/reporting/reporthtml.py index 41fbad59a76..c4d33f135c9 100644 --- a/modules/reporting/reporthtml.py +++ b/modules/reporting/reporthtml.py @@ -20,6 +20,16 @@ try: from jinja2.environment import Environment from jinja2.loaders import FileSystemLoader + from jinja2.ext import Extension + + class DjangoLoadExtension(Extension): + tags = {"load"} + + def parse(self, parser): + next(parser.stream) + while parser.stream.current.type != "block_end": + next(parser.stream) + return [] HAVE_JINJA2 = True except ImportError: @@ -107,7 +117,7 @@ def run(self, results): except Exception as e: log.warning("Could not read debugger logs for HTML report: %s", e) - env = Environment(autoescape=True) + env = Environment(autoescape=True, extensions=[DjangoLoadExtension]) env.filters.update( { "getkey": getkey, From 7e649e40c7d16cbb5d6bf28b9f8d6ceb3d97a95e Mon Sep 17 00:00:00 2001 From: doomedraven Date: Tue, 8 Sep 2026 09:13:51 +0200 Subject: [PATCH 2/5] Start Thread aux correctly and fix join warning (#3216) Handle auxiliary modules that are threading.Thread instances by calling Thread.start(aux) while preserving aux.start() for other types. Also correct the failed-join warning to include the auxiliary class name. Changes applied to analyzer/linux/analyzer.py and analyzer/windows/analyzer.py to improve thread startup reliability and logging clarity. --- analyzer/linux/analyzer.py | 5 ++++- analyzer/windows/analyzer.py | 7 +++++-- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/analyzer/linux/analyzer.py b/analyzer/linux/analyzer.py index ca5beca1f2b..24e700b0c4a 100644 --- a/analyzer/linux/analyzer.py +++ b/analyzer/linux/analyzer.py @@ -278,7 +278,10 @@ def run(self): log.debug('Initialized auxiliary module "%s"', module.__name__) aux_avail.append(aux) log.debug('Trying to start auxiliary module "%s"...', module.__name__) - aux.start() + if isinstance(aux, Thread): + Thread.start(aux) + else: + aux.start() log.debug('Started auxiliary module "%s"', module.__name__) aux_enabled.append(aux) except (NotImplementedError, AttributeError): diff --git a/analyzer/windows/analyzer.py b/analyzer/windows/analyzer.py index dd7a895757a..b8cacef770a 100644 --- a/analyzer/windows/analyzer.py +++ b/analyzer/windows/analyzer.py @@ -602,7 +602,10 @@ def get_all_subclasses(cls): aux_modules.append(aux) configure_aux_from_data(aux) log.debug('Trying to start auxiliary module "%s"...', module.__module__) - aux.start() + if isinstance(aux, Thread): + Thread.start(aux) + else: + aux.start() except (NotImplementedError, AttributeError) as e: log.warning("Auxiliary module %s was not implemented: %s", module.__name__, e) except Exception as e: @@ -874,7 +877,7 @@ def analysis_loop(self, aux_modules): if isinstance(aux, Thread): aux.join(timeout=10) if aux.is_alive(): - log.warning("Failed to join {aux} thread.") + log.warning("Failed to join %s thread.", aux.__class__.__name__) except (NotImplementedError, AttributeError): continue except Exception as e: From da7575666b502148b546e23ded00eabaa6d90107 Mon Sep 17 00:00:00 2001 From: Artur Lebedev Date: Tue, 8 Sep 2026 10:28:19 +0300 Subject: [PATCH 3/5] Update linux_agent.sh (#3207) Addition for #3138 - pyasyncore and setuptools for python > 3.11 --- extra/linux_agent.sh | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extra/linux_agent.sh b/extra/linux_agent.sh index 37be71f214a..77577d42222 100755 --- a/extra/linux_agent.sh +++ b/extra/linux_agent.sh @@ -3,6 +3,9 @@ # Install dependencies sudo apt update sudo apt install build-essential curl net-tools python3-pip python3-pyinotify systemtap-runtime ca-certificates curl gnupg lsb-release -y +if [ "$(python3 -c 'import sys; print(1 if sys.version_info > (3, 11) else 0)')" -eq "1" ]; then + sudo apt install -y python3-pyasyncore python3-setuptools +fi # agent.py installation sudo mkdir /root/.cape From 769145d4b5c8e3a17c95de7dbc64a75f5a80970e Mon Sep 17 00:00:00 2001 From: doomedraven Date: Tue, 8 Sep 2026 09:51:22 +0200 Subject: [PATCH 4/5] clamav sigs (#3205) * Update cape2.sh * Update cape2.sh --- installer/cape2.sh | 160 +++++++++++---------------------------------- 1 file changed, 39 insertions(+), 121 deletions(-) diff --git a/installer/cape2.sh b/installer/cape2.sh index 78cff6d55ae..1bb76ccb84b 100755 --- a/installer/cape2.sh +++ b/installer/cape2.sh @@ -1267,132 +1267,50 @@ EOF function install_clamav() { echo "[+] Installing clamav" - sudo apt-get install -y clamav clamav-daemon clamav-freshclam clamav-unofficial-sigs python3-pyclamd - - cat >> /usr/share/clamav-unofficial-sigs/conf.d/00-clamav-unofficial-sigs.conf << EOF -# This file contains user configuration settings for the clamav-unofficial-sigs.sh -# Script provide by Bill Landry (unofficialsigs@gmail.com). -# Script updates can be found at: http://sourceforge.net/projects/unofficial-sigs -# License: BSD (Berkeley Software Distribution) -PATH="/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin" -export PATH -clam_user="clamav" -clam_group="clamav" -setmode="yes" -clam_dbs="/var/lib/clamav" -clamd_pid="/var/run/clamd.pid" -reload_dbs="no" -reload_opt="clamdscan --reload" # Default -enable_random="yes" -min_sleep_time="60" # Default minimum is 60 seconds (1 minute). -max_sleep_time="600" # Default maximum is 600 seconds (10 minutes). -# ======================== -# Sanesecurity Database(s) -# ======================== -# http://www.sanesecurity.com/clamav/databases.htm -ss_dbs=" - blurl.ndb - junk.ndb - jurlbl.ndb - phish.ndb - rogue.hdb - sanesecurity.ftm - scam.ndb - sigwhitelist.ign2 - spamattach.hdb - spamimg.hdb - winnow.attachments.hdb - winnow_bad_cw.hdb - winnow_extended_malware.hdb - winnow_malware.hdb - winnow_malware_links.ndb - doppelstern.hdb - bofhland_cracked_URL.ndb - bofhland_malware_attach.hdb - bofhland_malware_URL.ndb - bofhland_phishing_URL.ndb - crdfam.clamav.hdb - phishtank.ndb - porcupine.ndb - foxhole_filename.cdb - foxhole_all.cdb -" -# ======================== -# SecuriteInfo Database(s) -# ======================== -si_dbs=" - honeynet.hdb - securiteinfo.hdb - securiteinfobat.hdb - securiteinfodos.hdb - securiteinfoelf.hdb - securiteinfohtml.hdb - securiteinfooffice.hdb - securiteinfopdf.hdb - securiteinfosh.hdb -" -si_update_hours="4" # Default is 4 hours (6 update checks daily). -mbl_dbs=" - mbl.ndb -" -mbl_update_hours="6" # Default is 6 hours (4 downloads daily). -rsync_connect_timeout="15" -rsync_max_time="60" -curl_connect_timeout="15" -curl_max_time="90" -work_dir="/usr/unofficial-dbs" #Top level working directory -# Sub-directory names: -ss_dir="$work_dir/ss-dbs" # Sanesecurity sub-directory -si_dir="$work_dir/si-dbs" # SecuriteInfo sub-directory -mbl_dir="$work_dir/mbl-dbs" # MalwarePatrol sub-directory -config_dir="$work_dir/configs" # Script configs sub-directory -gpg_dir="$work_dir/gpg-key" # Sanesecurity GPG Key sub-directory -add_dir="$work_dir/add-dbs" # User defined databases sub-directory -# If you would like to make a backup copy of the current running database -# file before updating, leave the following variable set to "yes" and a -# backup copy of the file will be created in the production directory -# with -bak appended to the file name. -keep_db_backup="no" -# If you want to silence the information reported by curl, rsync, gpg -# or the general script comments, change the following variables to -# "yes". If all variables are set to "yes", the script will output -# nothing except error conditions. -curl_silence="no" # Default is "no" to report curl statistics -rsync_silence="no" # Default is "no" to report rsync statistics -gpg_silence="no" # Default is "no" to report gpg signature status -comment_silence="no" # Default is "no" to report script comments -# Log update information to '$log_file_path/$log_file_name'. -enable_logging="yes" -log_file_path="/var/log" -log_file_name="clamav-unofficial-sigs.log" -# If necessary to proxy database downloads, define the rsync and/or curl -# proxy settings here. For rsync, the proxy must support connections to -# port 873. Both curl and rsync proxy setting need to be defined in the -# format of "hostname:port". For curl, also note the -x and -U flags, -# which must be set as "-x hostname:port" and "-U username:password". -rsync_proxy="" -curl_proxy="" -# After you have completed the configuration of this file, set the -# following variable to "yes". -user_configuration_complete="no" -################################################################################ -# END OF USER CONFIGURATION # -################################################################################ -add_dbs=" - https://raw.githubusercontent.com/wmetcalf/clam-punch/master/miscreantpunch099.ldb - https://raw.githubusercontent.com/wmetcalf/clam-punch/master/exexor99.ldb - https://raw.githubusercontent.com/twinwave-security/twinclams/master/twinclams.ldb - https://raw.githubusercontent.com/twinwave-security/twinclams/master/twinwave.ign2 -" + sudo apt-get install -y clamav clamav-daemon clamav-freshclam python3-pyclamd + + # Create configuration and working directories + sudo mkdir -p /etc/clamav-unofficial-sigs + sudo mkdir -p /var/lib/clamav-unofficial-sigs + sudo mkdir -p /var/log/clamav-unofficial-sigs + sudo chown -R clamav:clamav /var/lib/clamav-unofficial-sigs + sudo chown -R clamav:clamav /var/log/clamav-unofficial-sigs + + # Download script and configuration templates from extremeshok's official repo + sudo wget https://raw.githubusercontent.com/extremeshok/clamav-unofficial-sigs/master/clamav-unofficial-sigs.sh -O /usr/local/sbin/clamav-unofficial-sigs.sh + sudo chmod 755 /usr/local/sbin/clamav-unofficial-sigs.sh + sudo ln -sf /usr/local/sbin/clamav-unofficial-sigs.sh /usr/local/sbin/clamav-unofficial-sigs + + sudo wget https://raw.githubusercontent.com/extremeshok/clamav-unofficial-sigs/master/config/master.conf -O /etc/clamav-unofficial-sigs/master.conf + sudo wget https://raw.githubusercontent.com/extremeshok/clamav-unofficial-sigs/master/config/user.conf -O /etc/clamav-unofficial-sigs/user.conf + sudo wget https://raw.githubusercontent.com/extremeshok/clamav-unofficial-sigs/master/config/os/os.ubuntu.conf -O /etc/clamav-unofficial-sigs/os.conf + + # Override configurations in user.conf + sudo tee -a /etc/clamav-unofficial-sigs/user.conf > /dev/null << EOF + +# CAPEv2 custom additions +user_configuration_complete="yes" +additional_dbs=( + "https://raw.githubusercontent.com/wmetcalf/clam-punch/master/miscreantpunch099.ldb" + "https://raw.githubusercontent.com/wmetcalf/clam-punch/master/exexor99.ldb" + "https://raw.githubusercontent.com/twinwave-security/twinclams/master/twinclams.ldb" + "https://raw.githubusercontent.com/twinwave-security/twinclams/master/twinwave.ign2" +) EOF - chown root:root /usr/share/clamav-unofficial-sigs/conf.d/00-clamav-unofficial-sigs.conf - chmod 644 /usr/share/clamav-unofficial-sigs/conf.d/00-clamav-unofficial-sigs.conf - usermod -a -G ${USER} clamav + + sudo usermod -a -G ${USER} clamav echo "$CAPE_ROOT/storage/** r," | sudo tee -a /etc/apparmor.d/local/usr.sbin.clamd sudo apparmor_parser -r /etc/apparmor.d/usr.sbin.clamd sudo systemctl enable clamav-daemon sudo systemctl start clamav-daemon - sudo -u clamav /usr/sbin/clamav-unofficial-sigs + + # Run setup/installation commands of the unofficial sigs script + sudo /usr/local/sbin/clamav-unofficial-sigs.sh --install-cron + sudo /usr/local/sbin/clamav-unofficial-sigs.sh --install-logrotate + sudo /usr/local/sbin/clamav-unofficial-sigs.sh --install-man + + # Run the script to download the initial signatures as clamav user + sudo -u clamav /usr/local/sbin/clamav-unofficial-sigs.sh } function install_CAPE() { From eca604436e0ddc23b030938b60257da3c14a0b10 Mon Sep 17 00:00:00 2001 From: doomedraven Date: Tue, 8 Sep 2026 10:19:49 +0200 Subject: [PATCH 5/5] Update allauth_adapters.py --- web/web/allauth_adapters.py | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/web/web/allauth_adapters.py b/web/web/allauth_adapters.py index 421af62bf97..1fc02ccccec 100644 --- a/web/web/allauth_adapters.py +++ b/web/web/allauth_adapters.py @@ -361,9 +361,15 @@ def user_signed_up_(request, user, **kwargs): @receiver(email_confirmed) def email_confirmed_(request, email_address, **kwargs): - user = User.objects.get(email=email_address.email) - user.is_active = not settings.MANUAL_APPROVE - user.save() + try: + user = email_address.user + if user: + user.is_active = not settings.MANUAL_APPROVE + user.save() + else: + log.warning("email_confirmed signal received but email_address.user is None for %s", email_address.email) + except Exception as e: + log.error("Error activating user after email confirmation for %s: %s", email_address.email, e) class MySocialAccountAdapter(DefaultSocialAccountAdapter):