Unable to create XML file from AFR

Frank's Avatar

Frank

07 Jul, 2016 09:21 PM

I'm trying to create an XML file from the attached AFR, and I'm unsuccessful. I get an error from the command line using the arachni_reporter executable. I imported it into the database, with the arachni_web_scan_import, and I can view it with the Web user interface, but I still can't download and XML version. I get a 500 error. Using version 1.4 - WebUI v0.5.10.

Other formats have no issue (HTML, JSON, TXT, YAML) from the command line and web UI.

  1. Support Staff 1 Posted by Tasos Laskos on 08 Jul, 2016 04:40 AM

    Tasos Laskos's Avatar

    Hello, this issue has been resolved in the nightlies: http://downloads.arachni-scanner.com/nightlies/

  2. Tasos Laskos closed this discussion on 08 Jul, 2016 04:40 AM.

  3. Frank re-opened this discussion on 27 Oct, 2016 06:14 PM

  4. 2 Posted by Frank on 27 Oct, 2016 06:14 PM

    Frank's Avatar

    I have to re-open this. I have two different AFR files, from two different applications, that are unable to be converted to XML. Both contain the error message:

    [-] [utilities#exception_jail:428] [ArgumentError] string contains null byte

    I'm able to convert the AFR to HTML and TXT with no issue.

    I have attempted this with the nightly build from 10/26.

  5. Support Staff 3 Posted by Tasos Laskos on 27 Oct, 2016 06:34 PM

    Tasos Laskos's Avatar

    Can you show me the entire backtrace please?

  6. Support Staff 4 Posted by Tasos Laskos on 27 Oct, 2016 06:40 PM

    Tasos Laskos's Avatar

    Also, having the AFR would let me solve this quickly.

  7. 5 Posted by Frank on 28 Oct, 2016 01:13 PM

    Frank's Avatar

    Can I privately share the AFR with you?

  8. Support Staff 6 Posted by Tasos Laskos on 28 Oct, 2016 01:14 PM

    Tasos Laskos's Avatar

    Sure: tasos[dot]laskos[at]arachni-scanner.com

  9. 7 Posted by Frank on 28 Oct, 2016 02:43 PM

    Frank's Avatar

    Sent

  10. Support Staff 8 Posted by Tasos Laskos on 28 Oct, 2016 05:51 PM

    Tasos Laskos's Avatar

    Fix is in the nightlies.

    E-mail discussion summary:

    Had forgotten to apply the original fix to plugin XML formatters.

    Let me know how it works.

  11. 9 Posted by Frank on 30 Oct, 2016 03:18 PM

    Frank's Avatar

    The conversion to XML is working with the fix in the nightlies, but did anything change in the structure of the XML? I'm not able to import the XMLs into ThreadFix.

    When importing an XML I now see the error message "Failed to determine the scan type."

  12. Support Staff 10 Posted by Tasos Laskos on 30 Oct, 2016 04:55 PM

    Tasos Laskos's Avatar

    Yep, the nightlies include some schema updates.

  13. 11 Posted by Frank on 31 Oct, 2016 02:12 PM

    Frank's Avatar

    We import our scans into ThreadFix. This fix breaks that functionality for all our apps due to the schema update. It was only a couple of apps that had an issue with the null bytes, and a majority had no issue. I know that we will not be able to apply this update.

    Is there a way to make the fix without modifying the schema?

  14. Support Staff 12 Posted by Tasos Laskos on 31 Oct, 2016 02:37 PM

    Tasos Laskos's Avatar

    The schema update isn't relevant to the fix.
    You should contact the ThreadFix folks if you'd like it to support the upcoming version.

  15. Tasos Laskos closed this discussion on 28 Nov, 2016 03:28 PM.

  16. Frank re-opened this discussion on 29 Nov, 2016 07:00 PM

  17. 13 Posted by Frank on 29 Nov, 2016 07:00 PM

    Frank's Avatar

    We need this fix, but with the old schema. Is is possible to build the arachni_reporter to include this fix, but output an XML without the schema updates?

  18. Support Staff 14 Posted by Tasos Laskos on 01 Dec, 2016 11:22 AM

    Tasos Laskos's Avatar

    Sorry I can't do that.

  19. Tasos Laskos closed this discussion on 14 Dec, 2016 02:14 PM.

Comments are currently closed for this discussion. You can start a new one.

Keyboard shortcuts

Generic

? Show this help
ESC Blurs the current field

Comment Form

r Focus the comment reply box
^ + ↩ Submit the comment

You can use Command ⌘ instead of Control ^ on Mac