nuclei-templates/http/exposed-panels/axway-api-manager-panel.yaml

38 lines
1.2 KiB
YAML
Raw Normal View History

2023-05-26 01:47:10 +00:00
id: axway-api-manager-panel
info:
2023-05-26 12:57:19 +00:00
name: Axway API Manager Panel - Detect
2024-08-09 05:24:12 +00:00
author: johnk3r,righettod
2023-05-26 01:47:10 +00:00
severity: info
2024-08-09 05:24:12 +00:00
description: Axway API Manager panel was detected.
reference:
- https://docs.axway.com/bundle/axway-open-docs/page/docs/index.html
- https://www.postman.com/api-evangelist/axway/api/06c40de2-3954-4c68-ae10-a7eded330b05
- https://www.postman.com/api-evangelist/axway/api/ce2ac156-4353-46b9-b148-944ab7721ed6
2023-05-26 01:47:10 +00:00
metadata:
verified: true
2023-10-14 11:27:55 +00:00
max-request: 1
2023-07-22 07:58:18 +00:00
shodan-query: http.title:"Axway API Manager Login"
2024-08-09 05:24:12 +00:00
tags: panel,axway,detect,login
2023-05-26 01:47:10 +00:00
2023-05-26 11:57:06 +00:00
http:
2023-05-26 01:47:10 +00:00
- method: GET
path:
2024-08-09 05:24:12 +00:00
- "{{BaseURL}}/api/portal/v1.4/appinfo"
2023-05-26 01:47:10 +00:00
- "{{BaseURL}}"
2024-08-09 05:24:12 +00:00
stop-at-first-match: true
2023-05-26 01:47:10 +00:00
matchers:
2024-08-09 05:24:12 +00:00
- type: dsl
dsl:
- 'status_code == 200'
2024-08-09 15:26:51 +00:00
- 'contains_any(to_lower(body), "axway api manager login", "vordel/apiportal/app-login")'
2024-08-09 05:24:12 +00:00
condition: and
2023-05-26 01:47:10 +00:00
2024-08-09 05:24:12 +00:00
extractors:
- type: regex
part: body
group: 1
regex:
- '"productVersion":\s*"([0-9.]+)"'
2024-08-14 04:19:25 +00:00
# digest: 4a0a0047304502210088e48b3b04c31df518696d4c4bca07ba8d8e47dbfe30a1524b6b8688b09b092602202db671e4dabadf85931765723430da2e6c65368f8df6f0174bcc8d710d333bf1:922c64590222798bb761d5b6d8e72950