Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Files in PDFs always point to pdf.sysreptor.com #259

Open
firefart opened this issue May 23, 2024 · 5 comments
Open

Files in PDFs always point to pdf.sysreptor.com #259

firefart opened this issue May 23, 2024 · 5 comments

Comments

@firefart
Copy link

I noticed a weird bahviour in PDFs:
When you add a file to a finding via copy & paste it's shown as a link in the preview. When you generate a PDF the link alltough always points to https://pdf.sysreptor.com/files/name/FILENAME which is a leftover from the cloud version I guess.

Maybe it would be possible to add those files as a PDF attachment / embed them directly into the PDF?

@aronmolnar
Copy link
Contributor

Where do you come across this link in a rendered PDF?

Pasting files (except images) is not meant to be supported in SysReptor (and should result in an error).
image

Yet, there is an open ticket for embedding PDFs (but currently not on our roadmap) #41

(pdf.sysreptor.com is not a leftover from the cloud version, as we don't use this domain for our cloud customers. It's a "fake URL" which is set for the rendering process.)

image

@firefart
Copy link
Author

A colleague added some certificates into the notes of a report via copy and paste (p12 files) which end up under /files/name/xxxxxxxx.p12.
He then copied the note content over to the vuln and generated a PDF which resulted in the dummy links. I guess the copy from the notes just copied the /files/name/ path but those are not supported in the findings and the final pdf?

@aronmolnar
Copy link
Contributor

I see, you hackers :)

Yes, this is currently an unsupported scenario but is on our list which we will prioritize for H2 (see #240)

@MWedl
Copy link
Contributor

MWedl commented Jun 18, 2024

Let's track attaching files to PDFs in a separate issue #41

@MWedl MWedl closed this as completed Jun 18, 2024
@aronmolnar
Copy link
Contributor

Reopening this issue, as we should address this.

If a user copies the link to a file from notes to the report, SysReptor renders this as a link to pdf.sysreptor.com in the report:

image

This link leads to nowhere (and previously, there was an easter egg), which is an unintended behavior.

A pro customer sent a report with an allegedly attached document to a customer. The customer clicked the link and landed at the page with our easter egg, which is not a pleasant situation.

I think that we have the following options:

  • Support attaching PDF files as suggested in Ability to embed a document/object #41
  • Ignore files that are no images and don't reference them at all in the rendered PDF
    • In this case we must warn the pentester that the file will not be referenced in the PDF, either when pasting non-image links to markdown, or at the publish page

@aronmolnar aronmolnar reopened this Dec 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants