Replies: 1 comment
|
The 1ms failure on that command: cd /repos/api; ls -la; cat .gitignore; git ls-files ...almost always stems from one of two Git requirements inside Shannon's Docker container: 1. The mounted folder is not an initialized Git repository (Most Common)Shannon's If the folder you passed to Because the bash command chain fails on Fix: cd /path/to/your/backend-folder
git init
git add .
git commit -m "Initial commit for shannon scan"2. Git "Dubious Ownership" inside DockerShannon runs in a Docker container where commands execute under a specific user (often In Git 2.35.2+, if the mounted volume Fix: 3. Running purely "Blackbox" (URL only)Shannon is architected primarily as a white-box / hybrid grey-box security tester that correlates source code logic with runtime probes. If you don't want or have source code and want to run against only the target URL, you can pass a dummy empty Git repo to satisfy the mkdir /tmp/dummy-repo && cd /tmp/dummy-repo
git init
git commit --allow-empty -m "init"Then pass Initializing git in your backend source folder should get |
Uh oh!
There was an error while loading. Please reload this page.
Hello,
I'm trying out
shannonwith the objective of doing a blackbox assessment of my web app and so expected to run it with just an URL.As it turns out, the
-rparameter is required so I gave it the folder where the backend (AWS Lambda) sources are located.The process fails and I can see this in the log:
What have I missed?
All reactions