nuclei-templates/exposures/files/ds_store.yaml

32 lines
589 B
YAML
Raw Normal View History

2020-08-21 11:09:30 +00:00
id: ds-store-file
2020-08-21 10:51:02 +00:00
info:
name: Directory Listing via DS_Store
2020-08-21 10:51:02 +00:00
author: 0w4ys
2020-08-21 11:09:30 +00:00
severity: info
2021-04-06 06:46:11 +00:00
tags: file,exposure
2020-08-21 10:51:02 +00:00
requests:
- method: GET
path:
- "{{BaseURL}}/.DS_Store"
headers:
User-Agent: "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0"
2020-08-21 11:09:30 +00:00
2020-08-21 10:51:02 +00:00
matchers-condition: and
matchers:
- type: word
words:
- "\x00@\x00"
2020-08-21 11:09:30 +00:00
2020-08-21 10:51:02 +00:00
- type: status
status:
2020-08-21 11:09:30 +00:00
- 200
2020-08-21 10:51:02 +00:00
- type: word
words:
- "Accept-Ranges: bytes"
- "octet-stream"
condition: or
part: header