nuclei-templates/http/technologies/jsf-detect.yaml

37 lines
941 B
YAML
Raw Normal View History

id: jsf-detect
2021-05-27 08:17:14 +00:00
info:
name: JavaServer Faces Detection
2022-01-29 08:01:51 +00:00
author: brenocss,Moritz Nentwig
2021-05-28 04:17:29 +00:00
severity: info
2021-05-27 08:17:14 +00:00
description: Searches for JavaServer Faces content on a URL.
2022-01-29 08:01:51 +00:00
tags: jsf,tech,primefaces,richfaces
2021-05-27 08:17:14 +00:00
http:
2021-05-27 08:17:14 +00:00
- method: GET
path:
- "{{BaseURL}}"
host-redirects: true
max-redirects: 3
2022-01-29 05:01:15 +00:00
matchers-condition: or
2021-05-27 08:17:14 +00:00
matchers:
2022-01-29 05:01:15 +00:00
- type: dsl
name: javafaces
dsl:
2022-01-29 08:01:51 +00:00
- "(contains(body, 'javax.faces.resource') || contains(body, 'javax.faces.ViewState'))"
2022-01-29 05:01:15 +00:00
- type: dsl
name: primefaces
dsl:
2022-01-29 08:01:51 +00:00
- "contains(body, 'primefaces')"
- "contains(body, 'javax.faces.resource') || contains(body, 'javax.faces.ViewState')"
2022-01-29 05:01:15 +00:00
condition: and
- type: dsl
name: richfaces
dsl:
2022-01-29 08:01:51 +00:00
- "contains(body, 'richfaces')"
- "contains(body, 'javax.faces.resource') || contains(body, 'javax.faces.ViewState')"
2022-01-29 05:01:15 +00:00
condition: and