Skip to content

Feat: add lwn scraper - #160

Closed
EslamHiko wants to merge 6 commits into
aboutcode-org:developfrom
EslamHiko:scrape-lwn
Closed

Feat: add lwn scraper#160
EslamHiko wants to merge 6 commits into
aboutcode-org:developfrom
EslamHiko:scrape-lwn

Conversation

@EslamHiko

@EslamHiko EslamHiko commented Mar 12, 2020

Copy link
Copy Markdown
Contributor

This is a PR to solve: #77

This a sample data file shows the data I could collect (10 from items from each distributor) : sample-data.zip

small example :

{
  "chromium": [{
    "cve_ids": ["CVE-2020-6420"],
    "references": ["https://security.archlinux.org/AVG-1107", "https://chromereleases.googleblog.com/2020/03/stable-chan...", "https://crbug.com/1050996", "https://security.archlinux.org/CVE-2020-6420"],
    "summary": "[ASA-202003-1] chromium: access restriction bypass",
    "advisory_id": "ASA-202003-1",
    "distributor": "archlinux",
    "advisory_link": "https://lwn.net/Articles/814019"
  }, {
    "cve_ids": ["CVE-2020-6407", "CVE-2020-6418"],
    "references": ["https://security.archlinux.org/AVG-1102", "https://chromereleases.googleblog.com/2020/02/stable-chan...", "https://crbug.com/1045931", "https://crbug.com/1053604", "https://security.archlinux.org/CVE-2020-6407", "https://security.archlinux.org/CVE-2020-6418"],
    "summary": "[ASA-202002-11] chromium: multiple issues",
    "advisory_id": "ASA-202002-11",
    "distributor": "archlinux",
    "advisory_link": "https://lwn.net/Articles/813647"
  }, {
    "cve_ids": ["CVE-2020-6399", "CVE-2020-6390", "CVE-2020-6393", "CVE-2020-6403", "CVE-2020-6384", "CVE-2020-6387", "CVE-2020-6388", "CVE-2020-6407", "CVE-2020-6394", "CVE-2020-6411", "CVE-2020-6416", "CVE-2020-6386", "CVE-2020-6392", "CVE-2020-6383", "CVE-2020-6398", "CVE-2019-19880", "CVE-2019-19925", "CVE-2020-6409", "CVE-2020-6420", "CVE-2020-6391", "CVE-2020-6410", "CVE-2019-19923", "CVE-2020-6396", "CVE-2020-6413", "CVE-2020-6402", "CVE-2020-6389", "CVE-2020-6415", "CVE-2020-6400", "CVE-2020-6405", "CVE-2020-6418", "CVE-2020-6408", "CVE-2020-6401", "CVE-2020-6382", "CVE-2020-6412", "CVE-2020-6381", "CVE-2020-6414", "CVE-2020-6395", "CVE-2019-19926", "CVE-2020-6404", "CVE-2020-6397", "CVE-2020-6385", "CVE-2020-6406"],
    "references": ["https://www.debian.org/security/", "https://www.debian.org/security/faq", "https://security-tracker.debian.org/tracker/chromium", "https://www.debian.org/security/"],
    "summary": "[SECURITY] [DSA 4638-1] chromium security update",
    "advisory_id": "DSA-4638-1",
    "distributor": "debian",
    "advisory_link": "https://lwn.net/Articles/814560"
  }, {
    "cve_ids": ["CVE-2019-13677", "CVE-2019-13671", "CVE-2019-13685", "CVE-2019-13679", "CVE-2019-5872", "CVE-2019-13700", "CVE-2019-13660", "CVE-2019-13686", "CVE-2019-13714", "CVE-2019-13715", "CVE-2019-5880", "CVE-2019-13713", "CVE-2019-13694", "CVE-2019-13667", "CVE-2019-13696", "CVE-2019-13699", "CVE-2019-13717", "CVE-2019-13704", "CVE-2019-5878", "CVE-2019-13674", "CVE-2019-13693", "CVE-2019-13669", "CVE-2019-5869", "CVE-2019-13661", "CVE-2019-13688", "CVE-2019-13718", "CVE-2019-13683", "CVE-2019-13706", "CVE-2019-13707", "CVE-2019-13675", "CVE-2019-13716", "CVE-2019-13680", "CVE-2019-13678", "CVE-2019-13687", "CVE-2019-13664", "CVE-2019-13676", "CVE-2019-13682", "CVE-2019-13666", "CVE-2019-13701", "CVE-2019-13663", "CVE-2019-13710", "CVE-2019-5870", "CVE-2019-13697", "CVE-2019-13703", "CVE-2019-13662", "CVE-2019-5871", "CVE-2019-5876", "CVE-2019-5877", "CVE-2019-13673", "CVE-2019-5873", "CVE-2019-13721", "CVE-2019-13695", "CVE-2019-5881", "CVE-2019-13711", "CVE-2019-13705", "CVE-2019-13709", "CVE-2019-5874", "CVE-2019-13681", "CVE-2019-13708", "CVE-2019-13659", "CVE-2019-5879", "CVE-2019-13670", "CVE-2019-13665", "CVE-2019-13719", "CVE-2019-5875", "CVE-2019-13668"],
    "references": ["https://security.gentoo.org/", "https://nvd.nist.gov/vuln/detail/CVE-2019-13659", "https://nvd.nist.gov/vuln/detail/CVE-2019-13660", "https://nvd.nist.gov/vuln/detail/CVE-2019-13661", "https://nvd.nist.gov/vuln/detail/CVE-2019-13662", "https://nvd.nist.gov/vuln/detail/CVE-2019-13663", "https://nvd.nist.gov/vuln/detail/CVE-2019-13664", "https://nvd.nist.gov/vuln/detail/CVE-2019-13665", "https://nvd.nist.gov/vuln/detail/CVE-2019-13666", "https://nvd.nist.gov/vuln/detail/CVE-2019-13667", "https://nvd.nist.gov/vuln/detail/CVE-2019-13668", "https://nvd.nist.gov/vuln/detail/CVE-2019-13669", "https://nvd.nist.gov/vuln/detail/CVE-2019-13670", "https://nvd.nist.gov/vuln/detail/CVE-2019-13671", "https://nvd.nist.gov/vuln/detail/CVE-2019-13673", "https://nvd.nist.gov/vuln/detail/CVE-2019-13674", "https://nvd.nist.gov/vuln/detail/CVE-2019-13675", "https://nvd.nist.gov/vuln/detail/CVE-2019-13676", "https://nvd.nist.gov/vuln/detail/CVE-2019-13677", "https://nvd.nist.gov/vuln/detail/CVE-2019-13678", "https://nvd.nist.gov/vuln/detail/CVE-2019-13679", "https://nvd.nist.gov/vuln/detail/CVE-2019-13680", "https://nvd.nist.gov/vuln/detail/CVE-2019-13681", "https://nvd.nist.gov/vuln/detail/CVE-2019-13682", "https://nvd.nist.gov/vuln/detail/CVE-2019-13683", "https://nvd.nist.gov/vuln/detail/CVE-2019-13685", "https://nvd.nist.gov/vuln/detail/CVE-2019-13686", "https://nvd.nist.gov/vuln/detail/CVE-2019-13687", "https://nvd.nist.gov/vuln/detail/CVE-2019-13688", "https://nvd.nist.gov/vuln/detail/CVE-2019-13693", "https://nvd.nist.gov/vuln/detail/CVE-2019-13694", "https://nvd.nist.gov/vuln/detail/CVE-2019-13695", "https://nvd.nist.gov/vuln/detail/CVE-2019-13696", "https://nvd.nist.gov/vuln/detail/CVE-2019-13697", "https://nvd.nist.gov/vuln/detail/CVE-2019-13699", "https://nvd.nist.gov/vuln/detail/CVE-2019-13700", "https://nvd.nist.gov/vuln/detail/CVE-2019-13701", "https://nvd.nist.gov/vuln/detail/CVE-2019-13703", "https://nvd.nist.gov/vuln/detail/CVE-2019-13704", "https://nvd.nist.gov/vuln/detail/CVE-2019-13705", "https://nvd.nist.gov/vuln/detail/CVE-2019-13706", "https://nvd.nist.gov/vuln/detail/CVE-2019-13707", "https://nvd.nist.gov/vuln/detail/CVE-2019-13708", "https://nvd.nist.gov/vuln/detail/CVE-2019-13709", "https://nvd.nist.gov/vuln/detail/CVE-2019-13710", "https://nvd.nist.gov/vuln/detail/CVE-2019-13711", "https://nvd.nist.gov/vuln/detail/CVE-2019-13713", "https://nvd.nist.gov/vuln/detail/CVE-2019-13714", "https://nvd.nist.gov/vuln/detail/CVE-2019-13715", "https://nvd.nist.gov/vuln/detail/CVE-2019-13716", "https://nvd.nist.gov/vuln/detail/CVE-2019-13717", "https://nvd.nist.gov/vuln/detail/CVE-2019-13718", "https://nvd.nist.gov/vuln/detail/CVE-2019-13719", "https://nvd.nist.gov/vuln/detail/CVE-2019-13721", "https://nvd.nist.gov/vuln/detail/CVE-2019-5869", "https://nvd.nist.gov/vuln/detail/CVE-2019-5870", "https://nvd.nist.gov/vuln/detail/CVE-2019-5871", "https://nvd.nist.gov/vuln/detail/CVE-2019-5872", "https://nvd.nist.gov/vuln/detail/CVE-2019-5873", "https://nvd.nist.gov/vuln/detail/CVE-2019-5874", "https://nvd.nist.gov/vuln/detail/CVE-2019-5875", "https://nvd.nist.gov/vuln/detail/CVE-2019-5876", "https://nvd.nist.gov/vuln/detail/CVE-2019-5877", "https://nvd.nist.gov/vuln/detail/CVE-2019-5878", "https://nvd.nist.gov/vuln/detail/CVE-2019-5879", "https://nvd.nist.gov/vuln/detail/CVE-2019-5880", "https://nvd.nist.gov/vuln/detail/CVE-2019-5881", "https://security.gentoo.org/glsa/201911-06", "https://bugs.gentoo.org.", "https://creativecommons.org/licenses/by-sa/2.5"],
    "summary": "[gentoo-announce] [ GLSA 201911-06 ] Chromium, Google Chrome: Multiple vulnerabilities",
    "advisory_id": "201911-06",
    "distributor": "gentoo",
    "advisory_link": "https://lwn.net/Articles/805509"
  }]
}

Signed-off-by: Islam ElHakmi <eslam.elhakmey3@gmail.com>
Signed-off-by: Islam ElHakmi <eslam.elhakmey3@gmail.com>
Signed-off-by: Islam ElHakmi <eslam.elhakmey3@gmail.com>
Signed-off-by: Islam ElHakmi <eslam.elhakmey3@gmail.com>
Signed-off-by: Islam ElHakmi <eslam.elhakmey3@gmail.com>
@pombredanne

Copy link
Copy Markdown
Member

@EslamHiko thanks you ... this is looking very good at first glance! @sbs2001 @haikoschol your review is welcomed.

dists = getDistributors()
packagesVulns = {}
for dist in dists:
distUrl = base_url + "Alerts/" + dist + "?n=100"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"?n=100" how about not hardcoding this. Consider iterating every page(n=0 to n=last page)

@EslamHiko EslamHiko Mar 13, 2020

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sbs2001 n isn't the page number it's how many packages to show in the table after the offset, the default value is 20 & the max is 100.
ex : https://lwn.net/Alerts/Ubuntu/?n=20 & https://lwn.net/Alerts/Ubuntu/?n=100 & https://lwn.net/Alerts/Ubuntu/?n=200

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My bad

Comment thread vulnerabilities/scraper/lwn.py Outdated
@@ -0,0 +1,118 @@
# Author: Navonil Das (@NavonilDas)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider removing this, or put your name instead :))

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

Comment thread vulnerabilities/scraper/lwn.py Outdated
text = articleSoup.get_text()
total = int(text[text.find("(") + 1:text.find(")")].split()[0])
curr_offset = 0
while curr_offset < total:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could use a for curr_offset in range(0,total,100)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

base_url = "https://lwn.net/"


def extractPackageData(advisoryLink, dist, advisoryId):

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This misses the key component, package's version, please extract the package version and refactor that in data dump.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can't find a way to scrape the versions of the packages, but we can get the CVE if there's a source we can use it to get the versions I'll work on it. any ideas for it?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I haven't seen all the 'articles', so I may be wrong :) but it seems Gentoo,Fedora,Oracle distributions are providing patched or vulnerable versions of the package and they do follow a pattern. I think those could be extracted. Vulnerabilities without vulnerable packages are kind of useless. BTW we already have a scraper for Debian,Archlinux,Ubuntu so those could be safely skipped in this scraper.

Signed-off-by: Islam ElHakmi <eslam.elhakmey3@gmail.com>
'cve_ids': cves,
'references': references,
'summary': summary,
'advisory_id': advisoryId,

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure how this is handled for Gentoo but by looking at the sample data given

......
"summary": "[gentoo-announce] [ GLSA 201911-07 ] Mozilla Firefox: Multiple vulnerabilities",
   "advisory_id": "201911-07",
......

I think it will be more correct if it looked something like this "advisory_id":" GLSA 201911-07" . Ofcourse that would mean crafting separate logic for gentoo(mailing lists are painful)

@haikoschol

Copy link
Copy Markdown
Collaborator

@EslamHiko thanks you ... this is looking very good at first glance! @sbs2001 @haikoschol your review is welcomed.

It does? I thought we wanted to get rid of the little web scraping we have, not add more. Why do we even have a ticket about LWN? What exactly is the information they publish? After looking around a bit it seems like it's just security advisories from various Linux distributions. I think we should get that data from the distributions directly, in a machine-readable format.

@sbs2001

sbs2001 commented Mar 14, 2020

Copy link
Copy Markdown
Collaborator

@EslamHiko thanks you ... this is looking very good at first glance! @sbs2001 @haikoschol your review is welcomed.

It does? I thought we wanted to get rid of the little web scraping we have, not add more. Why do we even have a ticket about LWN? What exactly is the information they publish? After looking around a bit it seems like it's just security advisories from various Linux distributions. I think we should get that data from the distributions directly, in a machine-readable format.

I think this came up earlier(about giving a second thought to every data collection ticket). We need to flag duplicates(in this case lwn debian is duplicate of debian json) and eliminate human-readable advisories as much as possible.
I am afraid we might still need to some web-scraping,when no machine-readable data exists and the advisory contains unique data(again this needs verfication). Maybe create a ticket for this ?

@haikoschol

Copy link
Copy Markdown
Collaborator

I thought we wanted to get rid of the little web scraping we have, not add more. Why do we even have a ticket about LWN?

I think this came up earlier(about giving a second thought to every data collection ticket). We need to flag duplicates(in this case lwn debian is duplicate of debian json) and eliminate human-readable advisories as much as possible.

Pretty much all tickets that are not bugs or part of any milestones should be considered a brain dump; reminders to look into potential data sources and decide whether we want to write code for that. It is possible that there are duplicates or overlapping scope in those bazillion tickets but that's a secondary concern, after the initial research about a potential data source has been done.

@EslamHiko Of course there was no way for you to know that. I'm sorry that you put in so much effort here. This project is just woefully unprepared to accept contributions. Apart from the need to categorize and flesh out the tickets, there are some fundamentals that need to be straightened out before it makes sense to write dozens of importers.

I am afraid we might still need to some web-scraping,when no machine-readable data exists and the advisory contains unique data(again this needs verfication). Maybe create a ticket for this ?

To me this is a decision on our side and personally I would decide not to bother with web scraping. We could use a ticket to discuss this questions. That's probably a more appropriate place than the chat or comments on pull requests.

@EslamHiko

Copy link
Copy Markdown
Contributor Author

@haikoschol no problems at all I'll take a look at the milestones.

@haikoschol haikoschol closed this Mar 22, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants