Merge pull request #10753 from righettod/domibus_add

Add detection of DOMIBUS instances.
patch-11
Ritik Chaddha 2024-09-17 07:09:45 +04:00 committed by GitHub
commit 1177b5cb03
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 36 additions and 0 deletions

View File

@ -0,0 +1,36 @@
id: domibus-detect
info:
name: Domibus - Detect
author: righettod
severity: info
description: |
Domibus was detected.
reference:
- https://ec.europa.eu/digital-building-blocks/sites/display/DIGITAL/Domibus
metadata:
verified: true
max-request: 1
shodan-query: http.title:"Domibus"
tags: tech,domibus,detect
http:
- method: GET
path:
- "{{BaseURL}}/domibus/rest/application/info"
- "{{BaseURL}}/domibus/"
stop-at-first-match: true
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains_any(to_lower(body), "<title>domibus", "domibus-msh")'
condition: and
extractors:
- type: regex
part: body
group: 1
regex:
- '"versionNumber":\s*"([0-9.]+)"'