2020-05-05 11:01:22 +00:00
|
|
|
id: slack-access-token
|
|
|
|
|
2020-05-25 11:52:12 +00:00
|
|
|
# xoxp-702234529XXX-688970480XXX-109182524XXXX-87fa5b4d2e62ac5c16fc6ea93bXXXXXX
|
|
|
|
# xoxb-702234529XXX-1076883857XXX-Ou9aRuvtFZ4DuTsepevXXXXX
|
2020-05-05 11:01:22 +00:00
|
|
|
|
|
|
|
info:
|
|
|
|
name: Slack access token
|
|
|
|
author: nadino
|
|
|
|
severity: medium
|
|
|
|
|
|
|
|
requests:
|
|
|
|
- method: GET
|
|
|
|
path:
|
2020-05-09 08:59:35 +00:00
|
|
|
- "{{BaseURL}}"
|
2020-07-11 05:50:35 +00:00
|
|
|
|
|
|
|
matchers-condition: and
|
2020-05-05 11:01:22 +00:00
|
|
|
matchers:
|
|
|
|
- type: regex
|
|
|
|
part: body
|
|
|
|
regex:
|
2020-05-25 08:24:39 +00:00
|
|
|
- "xoxp-[0-9A-Za-z\\-]{72}" # Person
|
|
|
|
- "xoxb-[0-9A-Za-z\\-]{51}" # Bot
|
2020-05-05 11:01:22 +00:00
|
|
|
extractors:
|
|
|
|
- type: regex
|
|
|
|
part: body
|
|
|
|
regex:
|
|
|
|
- "xoxp-[0-9A-Za-z\\-]{72}"
|
|
|
|
- "xoxb-[0-9A-Za-z\\-]{51}"
|