From 0e8dfa9c6d5cc9bfad33193f3eb55311886a744c Mon Sep 17 00:00:00 2001 From: Ritik Chaddha <44563978+ritikchaddha@users.noreply.github.com> Date: Wed, 10 Jul 2024 23:44:21 +0530 Subject: [PATCH] Update snoop-servlet-exposure.yaml --- http/exposures/configs/snoop-servlet-exposure.yaml | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/http/exposures/configs/snoop-servlet-exposure.yaml b/http/exposures/configs/snoop-servlet-exposure.yaml index 5ff4d3f827..166a8c3c9b 100644 --- a/http/exposures/configs/snoop-servlet-exposure.yaml +++ b/http/exposures/configs/snoop-servlet-exposure.yaml @@ -1,20 +1,24 @@ id: snoop-servlet info: - name: Snoop Servlet information disclosure + name: Snoop Servlet - Information Disclosure author: omranisecurity severity: low - description: The Snoop Servlet returns information about the HTTP request itself and sometimes. It could help an attacker to prepare more advanced attacks. - reference: https://www.acunetix.com/vulnerabilities/web/snoop-servlet-information-disclosure/ + description: | + The Snoop Servlet returns information about the HTTP request itself and sometimes. It could help an attacker to prepare more advanced attacks. + reference: + - https://www.acunetix.com/vulnerabilities/\web/snoop-servlet-information-disclosure/ metadata: - shodan-query: http.title:"Snoop Servlet" - fofa-query: title=="Snoop Servlet" + max-request: 1 + shodan-query: title:"Snoop Servlet" + fofa-query: title="Snoop Servlet" tags: config,exposure,snoop,snoop-servlet http: - method: GET path: - "{{BaseURL}}/snoop" + matchers: - type: dsl dsl: