Wegweiser
All notes

What your clients' websites expose to the internet

A website scan now also brings back the Shodan record of the server behind the site: the services it exposes, the software and version behind each, what is past its end of life, and the CVEs matched to those versions, with the actively exploited ones first. On your own Shodan key, and the card no longer hides a scan that failed.

A Fenrir scan tells you what an attacker could do to your client's website. It said nothing about the server underneath it: the mail service open on the same address, the web server years past its last release, the management port nobody meant to publish. Every scan now looks that address up on Shodan and brings the record back with the findings.

Your own Shodan key

A master adds the key under Integrations > Fenrir. It is handed to your own Fenrir account, which checks it with Shodan and keeps it sealed; Wegweiser stores no copy of it, in the secret store, in a column, in the audit record or in a log line. The page shows what your Fenrir reports back: the last four characters, your Shodan plan, your query credits, and a warning when Shodan stopped accepting the key at a scan. Looking up a host spends no query credit.

No key, no lookup: it is your plan, your credits and your terms with Shodan, never ours, and until a key is added the card reads exactly as before.

What the card says

Under the coverage line, one sentence: "Server: 2 services exposed, nginx 1.24.0 past its end of life, 2 CVEs matched by version, 1 actively exploited". Open it and you get each service with its port, the software and version the server announces, its TLS versions and an end of life mark, then the CVEs, the ones CISA lists as exploited in the wild first. The website chat gets the same in one sentence, so "how is this site doing" answers with the server as well as the findings.

Three things are said wherever that is shown, because all three are true. The CVEs are Shodan's match on a version number and not a test, so a distribution that backports fixes under an old version number looks vulnerable when it is not. The services on a CDN edge are the CDN's, not your client's server. And the data is Shodan's, credited and linked to the host record. Shodan is now on the data sources page with what is sent and under whose account.

A scan that fails now says so

A four day outage at the scanner turned up a dozen places where a failure read as something else, and the card was the worst of them: it showed the last good scan and said nothing about a newer attempt that had come to nothing. The card and the chat now say when the newest run did not finish, with the scanner's own reason, or that it finished and its findings are not read in yet.

Underneath that: a scan the scanner lost no longer counts against that client's scans for the day, so a failure cannot lock a client out until tomorrow. A scan given up on is cancelled at the scanner, so it cannot go on sending traffic at a site nobody is reading the result of. A request that never got an answer is asked again under the same key, rather than starting a second scan against a live site. A completed scan whose findings could not be read is re-read for three days, and until they are in, nothing calls it the latest scan. The cadence sweep now looks through two hundred due websites instead of twelve, and stops while the scanner's worker is not working. And only a master can ask the card for a deeper scan than the default you set.

A quick check no longer closes what it cannot test

A passive check reads a website the way a visitor would. It cannot repeat the test attack that proved an injection, so it was recording those findings as fixed. Now it closes only what a passive rule found; everything an attack proved stays open and is marked "not re-tested by the passive check" on the card and in the chat, until a scan that attacks looks again.

Also in this release

One fault is one notice. The dashboard showed nine notices for a single hour long fault on our side, each naming all 34 affected machines. Notices that say the same thing are now one notice, every machine listed once and dismissed in one click, and a notice names five machines and folds the rest behind "and 29 more machines".

Tenant isolation is now in the database itself. Row level security is live on production on every table that holds a tenant's data, so a query that forgets its tenant returns nothing rather than another MSP's rows. The deploy check names any new table that would stand outside that fence.

Stored and generated HTML is sanitised in one place on its way into a page: helpdesk article bodies, analyses, the PDF reports, the message centre, and the public snapshot that anyone with the link opens without signing in.

Device credentials expire. The token that lets an agent hold its command channel is now good for thirty days and can be revoked at the broker, and agent 0.3.111 renews it ahead of time and keeps reconnecting through an authentication error instead of waiting for a restart.

The database leaves the box every night at 02:30 UTC, encrypted before it goes, verified after it is written and kept thirty days on a separate machine. The restore has been rehearsed onto staging rather than assumed, and an encrypted copy has been decrypted back to a byte for byte identical dump.

More notes

  1. Tell the scanner what you don't allow

  2. Agent release log

  3. MeshCentral, one click from the machine