Here's my report for week 4:
weevely - almost finished (will upload this week);
- finishing manpage.
wpscan - non-free software, low effort to upload it though;
- needs ruby-progressbar (>=1.6.0), which is being packaged on salsa.
- send email on ruby team's list to check status of package
ruby-progressbar, the required version o the package is
on salsa but failing some tests.
findmyhash - won't package right now;
zaproxy: needs to be repacked, lots of works and high chance of breaking without required lib's versions;
- lots of java libs bundled, will confirm with mentors the next steps or if we are gonna leave this package out.
dirbuster: integrated into zaproxy now, will focus on that package instead.
beef-xss: lots of libs that breaks and needs lots of tests to be written first;
- needs to package some rubygems, kali used to "proper" package beef-xss but the amount of
regressions lead them to change to a bundled package.
- add two fields on the spreadsheet:
~ MANUAL NOTES: notes about the package that didn't got catch by the script.
~ samueloph's conclusion: my thoughts about the packaging (TODO, WIP,WONT). Other people may add their conclusion's there too.
- update the
kali-packages-checker script to output the Section of the package (so we
know if the package is not on main already).
- fix problem with script where it would detect packages not-installed from official debian repo's as present on debian and thus missing some packages.
- update the script's output ods file and gdocs spreadsheet.
- report a problem with tagpending salsa integration explained on the team's wiki, the steps are not working
- discovered that lintian would probably benefit from a check for windows
binaries shipped on the package, mimikatz only ships windows
pre-compiled binaries and the only check which would get that is:
"source-contains-prebuilt-windows-binary", there should be a lintian "Error" tag there, probably. Still have to discuss that further with my mentors.
- talk with people about the mimikatz case to see if there's room for improvement for lintian on this case.
- the script is now properly reporting packages that are not on unstable, but the way it works it thinks virtual packages are never present on debian, should rework that part with a proper check for sid presence of a package.
- check for the packages sent by Gianfranco (13 packages) and package all the ones possible.
- finish the packaging of weevely, wpscan, and talk about the other packages with mentors.
- package python-shodan is still on the NEW queue, the changeme package will be uploaded right after.
- talked with mentors and i'll do a more verbose and better formatted report now. As a starter, i'll write the report as i do the tasks, not at the end of the week, this has led me to forget things and write poor reports.
Samuel Henrique <samueloph>