nuclei-templates/http/miscellaneous/defaced-website-detect.yaml

29 lines
737 B
YAML
Raw Normal View History

2023-08-19 05:35:01 +00:00
id: defaced-website-detect
2023-08-18 19:12:07 +00:00
info:
2023-08-19 05:35:01 +00:00
name: Defaced Website - Detection
2023-08-18 19:12:07 +00:00
author: ggranjus
severity: info
description: The detected website is defaced.
metadata:
verified: 'true'
max-request: 1
2023-10-14 11:27:55 +00:00
shodan-query: http.title:"Hacked By"
2024-01-14 09:21:50 +00:00
tags: miscellaneous,defacement,misc
2023-08-18 19:12:07 +00:00
http:
- method: GET
path:
- "{{BaseURL}}"
matchers:
- type: regex
2023-08-19 05:35:01 +00:00
part: body
2023-08-18 19:12:07 +00:00
regex:
- '(?i)<title>.*Hacked( By .+)?<\/title>'
2023-08-19 05:35:01 +00:00
2023-08-18 19:12:07 +00:00
extractors:
- type: xpath
xpath:
- '/html/head/title'
# digest: 4a0a004730450221008017206eef3294e64b224c423a46620964e66451b66a5c444a1e4fb5050dc10a0220069f2bdb68a10415f4d3ec5eff3478c39ecce08c45f8f02b192463f7867536de:922c64590222798bb761d5b6d8e72950