Fixed dns/elasticbeanstalk-takeover Template

patch-1
joaonevess 2023-09-27 08:54:47 -03:00
parent a5af4a1f44
commit 366d4a37b8
1 changed files with 2 additions and 2 deletions

View File

@ -2,7 +2,7 @@ id: elasticbeanstalk-takeover
info: info:
name: ElasticBeanstalk Subdomain Takeover Detection name: ElasticBeanstalk Subdomain Takeover Detection
author: philippedelteil,rotemreiss,zy9ard3 author: philippedelteil,rotemreiss,zy9ard3,joaonevess
severity: high severity: high
description: ElasticBeanstalk subdomain takeover detected. A subdomain takeover occurs when an attacker gains control over a subdomain of a target domain. Typically, this happens when the subdomain has a canonical description: ElasticBeanstalk subdomain takeover detected. A subdomain takeover occurs when an attacker gains control over a subdomain of a target domain. Typically, this happens when the subdomain has a canonical
name (CNAME) in the Domain Name System (DNS), but no host is providing content for it. name (CNAME) in the Domain Name System (DNS), but no host is providing content for it.
@ -35,7 +35,7 @@ dns:
matchers: matchers:
- type: regex - type: regex
regex: regex:
- CNAME\t.*\.(us|af|ap|ca|eu|me|sa)\-(east|west|south|northeast|southeast|central)\-[1-9]+\.elasticbeanstalk\.com - CNAME\t.*\.(us|af|ap|ca|eu|me|sa|il)\-(north|east|west|south|northeast|southeast|central)\-[1-9]+\.elasticbeanstalk\.com
- type: word - type: word
words: words: