Add whitelist and version check instructions to README
This commit is contained in:
27
README.md
27
README.md
@@ -55,6 +55,33 @@ After cloning, run `setup.sh` once. It will:
|
|||||||
- Send a test Telegram message confirming the VM is active
|
- Send a test Telegram message confirming the VM is active
|
||||||
- Create a `logs/` folder — logs are kept for 60 days then auto-deleted
|
- Create a `logs/` folder — logs are kept for 60 days then auto-deleted
|
||||||
|
|
||||||
|
## Whitelisting Known-Safe Findings
|
||||||
|
|
||||||
|
If a script flags something you know is safe, add it to `whitelist.conf` on that VM to suppress it in future scans. This file is VM-specific and never committed to git.
|
||||||
|
|
||||||
|
Add a package name:
|
||||||
|
```bash
|
||||||
|
echo "ua-parser-js" >> ~/security-tools/whitelist.conf
|
||||||
|
```
|
||||||
|
|
||||||
|
Add a file path:
|
||||||
|
```bash
|
||||||
|
echo "/tmp/my-known-script.sh" >> ~/security-tools/whitelist.conf
|
||||||
|
```
|
||||||
|
|
||||||
|
View or edit the whitelist:
|
||||||
|
```bash
|
||||||
|
nano ~/security-tools/whitelist.conf
|
||||||
|
```
|
||||||
|
|
||||||
|
## Checking Script Versions
|
||||||
|
|
||||||
|
To see which version of a script is running on a VM:
|
||||||
|
```bash
|
||||||
|
head -2 ~/security-tools/npm-security-check.sh
|
||||||
|
head -2 ~/security-tools/check-nextjs-rce.sh
|
||||||
|
```
|
||||||
|
|
||||||
## Updating an Existing VM
|
## Updating an Existing VM
|
||||||
|
|
||||||
When changes are pushed to this repo, update any VM by running:
|
When changes are pushed to this repo, update any VM by running:
|
||||||
|
|||||||
Reference in New Issue
Block a user