Skip to content

Fix ASP.NET WebForms issues in AdPentest.aspx - #72

Open
netanelcyber wants to merge 11 commits into
mainfrom
claude/project-thread-j3fjf7
Open

netanelcyber wants to merge 11 commits into
mainfrom
claude/project-thread-j3fjf7

Conversation

@netanelcyber

Copy link
Copy Markdown
Owner

Requested by NETANEL · project thread

Before: The page carried a deprecated EnableViewStateMac attribute, had an unobserved fire-and-forget async task in the cancellation callback, used fully-qualified System.Web.Hosting references inconsistently, had a double space in process arguments, displayed "careful" in the UI while the command used --active-search full, and left a SeverityClass Eval unencoded in a class attribute.

After: All six issues are resolved. The page directive is clean, the cancellation callback properly discards the Task, namespace usage is consistent, the argument string is correct, the UI text matches the actual command, and the severity class attribute is HTML-encoded for defense-in-depth.

The change removes a no-op attribute, adds one namespace import, and fixes five minor code/text issues — no behavioral change to the page.

How: Single-file edit to AdPentest.aspx covering the page directive, namespace imports, the RunScanBackgroundAsync cancellation registration, the ProcessStartInfo.Arguments string, the UI description in both Hebrew and English, and the CVE GridView template field.

🤖 Generated with Claude Code

https://claude.ai/code/session_012UJccLLHHrsJxUjpLbcx56


Generated by Claude Code

tenten48tenten and others added 11 commits September 16, 2026 17:18
feat: Jinja2-based interactive HTML pentest report generator (Closes #22)
Brings over AdPentest.aspx from the earlier session branch
(claude/eager-cray-4gl5be) with correct Page directive and assembly
references: EntityFramework, System.Data.SQLite, System.Data.SQLite.EF6,
Newtonsoft.Json, and System.ComponentModel.DataAnnotations.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- Include target in CVE dedup key so multi-host findings are not collapsed
- Validate CVE match entries are JObject before indexing
- Allow PopulateReport on truncated output (JSON may still be valid)
- Observe cancellation token to stop scan on app pool recycle
- Add fallbacks for target/mode fields to accept older report formats
- Fix confidence caption from "all low" to "low- to medium-confidence"

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- Validate Host header (localhost/127.0.0.1/[::1]) to block DNS-rebinding
  attacks against the IsLocal-only page
- Guard exit-code status assignment with !cancelled so "cancelled" status
  is not overwritten by "completed"/"failed"/"output-truncated"
- Check activeSearch is JObject before indexing into it

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- DrainAsync now reads up to 4 MiB (MaxParseChars) for report parsing
  while still capping the DB-stored display at 512 KiB, so large JSON
  reports are parsed correctly even when display output is truncated
- run_id is now optional in PopulateReport so sample/imported JSON
  without a run_id can be imported successfully
- When QueueBackgroundWorkItem fails, update the DB row from "queued"
  to "error" so it does not mislead operators

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
The row variable was declared inside try, making row.Id unreachable
in the catch block. Moved rowId declaration before try and added a
guard (rowId > 0) so the error-status update only runs after a
successful DB insert.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- output-truncated status only replaces "completed", preserving
  "failed" and "timeout" statuses when output is also truncated
- Target field in PopulateReport is now optional; falls back to
  row.RequestedTarget so CLI error reports without a target field
  are accepted
- Port list caption in Hebrew and English now matches the actual
  ports scanned by active_service_search in core.py

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
…mode

- stream-timeout no longer overwrites cancelled/timeout status
- PopulateReport runs whenever stdout completed, even during
  stream-timeout (stderr-only timeout no longer blocks parsing)
- Mode falls back to row.Mode for targetless error reports

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
Add ASP.NET Web Forms dashboard with verified page directives
- Remove deprecated EnableViewStateMac attribute (always enforced in .NET 4.5.2+)
- Add System.Web.Hosting namespace import and use short type names
- Fix fire-and-forget async in cancellation callback (discard Task explicitly
  instead of calling .ConfigureAwait(false) without await)
- Fix double space in process arguments string
- Fix UI text mismatch: active-search description said "careful" but command uses "full"
- HTML-encode SeverityClass Eval in class attribute for defense-in-depth

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012UJccLLHHrsJxUjpLbcx56
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@netanelcyber netanelcyber self-assigned this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants