template + matchers update

patch-1
sandeep 2022-03-11 14:18:36 +05:30
parent e12508b6e3
commit 3b3c26aec2
1 changed files with 30 additions and 19 deletions

View File

@ -1,35 +1,46 @@
id: apollo-default-login id: apollo-default-login
info: info:
name: Apollo Default Login name: Apollo Default Login
author: PaperPen author: PaperPen
severity: high severity: high
metadata:
shodan-query: http.favicon.hash:11794165
reference: https://github.com/apolloconfig/apollo
tags: apollo,default-login tags: apollo,default-login
requests: requests:
- raw: - raw:
- | - |
POST /signin HTTP/1.1 POST /signin HTTP/1.1
Host: {{Hostname}} Host: {{Hostname}}
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0 Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Origin: {{BaseURL}}
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2 Referer: {{BaseURL}}/signin?
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 62
Origin: {{BaseURL}}
DNT: 1
Connection: close
Referer: {{BaseURL}}/signin?
Upgrade-Insecure-Requests: 1
username=apollo&password=admin&login-submit=%E7%99%BB%E5%BD%95 username={{user}}&password={{pass}}&login-submit=Login
redirects: true - |
max-redirects: 3 GET /user HTTP/1.1
Host: {{Hostname}}
attack: pitchfork
payloads:
user:
- apollo
pass:
- admin
cookie-reuse: true cookie-reuse: true
req-condition: true
matchers: matchers:
- type: word - type: word
part: body_2
words: words:
- "media='all'" - '"userId":'
- '"email":'
condition: or
- type: status
status:
- 200