From 06f45f01943510ae8df0fe60fe48b9728f2891d2 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Sun, 10 Jul 2022 01:34:21 +0100 Subject: [PATCH] Create secret-token-rb.yaml --- exposures/files/secret-token-rb.yaml | 30 ++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 exposures/files/secret-token-rb.yaml diff --git a/exposures/files/secret-token-rb.yaml b/exposures/files/secret-token-rb.yaml new file mode 100644 index 0000000000..bd522d14cd --- /dev/null +++ b/exposures/files/secret-token-rb.yaml @@ -0,0 +1,30 @@ +id: secret-token-rb + +info: + name: Secret Token Ruby File Disclosure + author: DhiyaneshDK + severity: medium + metadata: + verified: true + google-query: intitle:"index of" "secret_token.rb" + tags: redmine,devops,exposure,ruby + +requests: + - method: GET + path: + - "{{BaseURL}}/secret_token.rb" + - "{{BaseURL}}/config/initializers/secret_token.rb" + - "{BaseURL}}/redmine/config/initializers/secret_token.rb" + + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + words: + - 'Application.config.secret' + condition: and + + - type: status + status: + - 200