From b5a3b1496284b90cc98353a2d7de25f9c0b79fe7 Mon Sep 17 00:00:00 2001 From: Dominique RIGHETTO Date: Sat, 14 Sep 2024 17:44:06 +0200 Subject: [PATCH] Add files via upload --- http/technologies/domibus-detect.yaml | 36 +++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 http/technologies/domibus-detect.yaml diff --git a/http/technologies/domibus-detect.yaml b/http/technologies/domibus-detect.yaml new file mode 100644 index 0000000000..85fa15c0c0 --- /dev/null +++ b/http/technologies/domibus-detect.yaml @@ -0,0 +1,36 @@ +id: domibus-detect + +info: + name: Domibus - Detect + author: righettod + severity: info + description: | + Domibus was detected. + reference: + - https://ec.europa.eu/digital-building-blocks/sites/display/DIGITAL/Domibus + metadata: + verified: true + max-request: 1 + shodan-query: http.title:"Domibus" + tags: tech,domibus,detect + +http: + - method: GET + path: + - "{{BaseURL}}/domibus/rest/application/info" + - "{{BaseURL}}/domibus/" + + stop-at-first-match: true + matchers: + - type: dsl + dsl: + - 'status_code == 200' + - 'contains_any(to_lower(body), "domibus", "domibus-msh")' + condition: and + + extractors: + - type: regex + part: body + group: 1 + regex: + - '"versionNumber":\s*"([0-9.]+)"' \ No newline at end of file