more tag supports

patch-1
sandeep 2021-04-03 13:38:45 +05:30
parent a1f2ecbc06
commit 3ef39c173e
66 changed files with 70 additions and 69 deletions

View File

@ -4,7 +4,7 @@ info:
name: OpenAPI name: OpenAPI
author: pdteam author: pdteam
severity: info severity: info
tags: api tags: exposures,api
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Public Swagger API name: Public Swagger API
author: pdteam author: pdteam
severity: info severity: info
tags: api,swagger tags: exposures,api,swagger
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: wadl file disclosure name: wadl file disclosure
author: 0xrudra & manuelbua author: 0xrudra & manuelbua
severity: info severity: info
tags: api tags: exposures,api
reference: | reference: |
- https://github.com/dwisiswant0/wadl-dumper - https://github.com/dwisiswant0/wadl-dumper
- https://www.nopsec.com/leveraging-exposed-wadl-xml-in-burp-suite/ - https://www.nopsec.com/leveraging-exposed-wadl-xml-in-burp-suite/

View File

@ -4,7 +4,7 @@ info:
name: wsdl-detect name: wsdl-detect
author: jarijaas author: jarijaas
severity: info severity: info
tags: api tags: exposures,api
description: Detects web services that have WSDL (https://www.w3.org/TR/wsdl/) description: Detects web services that have WSDL (https://www.w3.org/TR/wsdl/)
requests: requests:

View File

@ -4,7 +4,7 @@ info:
name: settings.php information disclosure name: settings.php information disclosure
author: sheikhrishad author: sheikhrishad
severity: medium severity: medium
tags: backup tags: exposures,backup
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: MySQL Dump Files name: MySQL Dump Files
author: geeknik & @dwisiswant0 author: geeknik & @dwisiswant0
severity: medium severity: medium
tags: backup tags: exposures,backup
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Compressed Web File name: Compressed Web File
author: Toufik Airane & @dwisiswant0 author: Toufik Airane & @dwisiswant0
severity: medium severity: medium
tags: backup tags: exposures,backup
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Apache Airflow Configuration Exposure name: Apache Airflow Configuration Exposure
author: pd-team author: pd-team
severity: medium severity: medium
tags: config tags: exposures,config
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Alibaba Canal Info Leak name: Alibaba Canal Info Leak
author: pikpikcu author: pikpikcu
severity: info severity: info
tags: config tags: config,exposures
# https://github.com/alibaba/canal/issues/632 # https://github.com/alibaba/canal/issues/632
# https://netty.io/wiki/reference-counted-objects.html # https://netty.io/wiki/reference-counted-objects.html

View File

@ -4,7 +4,7 @@ info:
name: Dockerrun AWS Configuration Exposure name: Dockerrun AWS Configuration Exposure
author: pd-team author: pd-team
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Ansible Configuration Exposure name: Ansible Configuration Exposure
author: pd-team author: pd-team
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: AWStats config name: AWStats config
author: sheikhrishad author: sheikhrishad
severity: info severity: info
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: AWStats script name: AWStats script
author: sheikhrishad author: sheikhrishad
severity: info severity: info
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: geeknik author: geeknik
severity: low severity: low
reference: https://circleci.com/docs/2.0/sample-config/ reference: https://circleci.com/docs/2.0/sample-config/
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: circleci ssh-config exposure name: circleci ssh-config exposure
author: geeknik author: geeknik
severity: low severity: low
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: composer-config-file name: composer-config-file
author: Mahendra Purbia (Mah3Sec_) author: Mahendra Purbia (Mah3Sec_)
severity: info severity: info
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: docker-compose.yml exposure name: docker-compose.yml exposure
author: meme-lord & blckraven & geeknik author: meme-lord & blckraven & geeknik
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: pikpikcu author: pikpikcu
severity: high severity: high
reference: https://www.cnvd.org.cn/flaw/show/CNVD-2021-10543 reference: https://www.cnvd.org.cn/flaw/show/CNVD-2021-10543
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: daffainfo author: daffainfo
severity: low severity: low
reference: https://www.bitkeeper.org/man/config-etc.html reference: https://www.bitkeeper.org/man/config-etc.html
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: daffainfo author: daffainfo
severity: low severity: low
reference: http://doc.bazaar.canonical.com/beta/en/user-reference/configuration-help.html reference: http://doc.bazaar.canonical.com/beta/en/user-reference/configuration-help.html
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: daffainfo author: daffainfo
severity: low severity: low
reference: http://darcs.net/Using/Configuration#sources reference: http://darcs.net/Using/Configuration#sources
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Exposed HG Directory name: Exposed HG Directory
author: daffainfo author: daffainfo
severity: low severity: low
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Exposed SVN Directory name: Exposed SVN Directory
author: udit_thakkur & dwisiswant0 author: udit_thakkur & dwisiswant0
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: FTP credentials exposure name: FTP credentials exposure
author: pikpikcu author: pikpikcu
severity: medium severity: medium
tags: config,ftp tags: config,ftp,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
author: organiccrap author: organiccrap
severity: medium severity: medium
description: Nginx off-by-slash vulnerability exposes Git configuration. description: Nginx off-by-slash vulnerability exposes Git configuration.
tags: config tags: config,exposures
reference: https://twitter.com/Random_Robbie/status/1262676628167110656 reference: https://twitter.com/Random_Robbie/status/1262676628167110656
requests: requests:

View File

@ -5,7 +5,7 @@ info:
author: pd-team & pikpikcu author: pd-team & pikpikcu
severity: medium severity: medium
description: Searches for the pattern /.git/config on passed URLs. description: Searches for the pattern /.git/config on passed URLs.
tags: config,git tags: config,git,exposures
requests: requests:
- raw: - raw:

View File

@ -5,7 +5,7 @@ info:
author: geeknik author: geeknik
severity: info severity: info
description: https://developers.google.com/gmail/api/auth/web-server description: https://developers.google.com/gmail/api/auth/web-server
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: dhiyaneshDK author: dhiyaneshDK
severity: low severity: low
reference: https://hackerone.com/reports/1026196 reference: https://hackerone.com/reports/1026196
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: alperenkesk author: alperenkesk
severity: low severity: low
reference: https://www.exploit-db.com/exploits/44734 reference: https://www.exploit-db.com/exploits/44734
tags: scada,config tags: scada,config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Detect exposed .htpasswd files name: Detect exposed .htpasswd files
author: geeknik author: geeknik
severity: info severity: info
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: oppsec author: oppsec
severity: low severity: low
description: configuration.php-dist is a file created by Joomla to save Joomla settings. description: configuration.php-dist is a file created by Joomla to save Joomla settings.
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Laravel .env file name: Laravel .env file
author: pxmme1337 & dwisiswant0 & geeknik & emenalf author: pxmme1337 & dwisiswant0 & geeknik & emenalf
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Lvmeng UTS Disclosure name: Lvmeng UTS Disclosure
author: pikpikcu author: pikpikcu
severity: high severity: high
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -3,7 +3,7 @@ info:
name: Magento Config Disclosure name: Magento Config Disclosure
author: geeknik author: geeknik
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -6,7 +6,7 @@ info:
description: The .netrc file contains login and initialization information used by the auto-login process. description: The .netrc file contains login and initialization information used by the auto-login process.
reference: https://www.gnu.org/software/inetutils/manual/html_node/The-_002enetrc-file.html reference: https://www.gnu.org/software/inetutils/manual/html_node/The-_002enetrc-file.html
severity: high severity: high
tags: netrc,config tags: netrc,config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: OPcache Status Exposure name: OPcache Status Exposure
author: pd-team author: pd-team
severity: low severity: low
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: owncloud config Disclosure name: owncloud config Disclosure
author: Mahendra Purbia (Mah3Sec_) author: Mahendra Purbia (Mah3Sec_)
severity: info severity: info
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: geeknik & afaq author: geeknik & afaq
severity: info severity: info
description: All npm packages contain a file, usually in the project root, called package.json - this file holds various metadata relevant to the project. description: All npm packages contain a file, usually in the project root, called package.json - this file holds various metadata relevant to the project.
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Apache mod_perl Status Page Exposure name: Apache mod_perl Status Page Exposure
author: pd-team author: pd-team
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: phpinfo Disclosure name: phpinfo Disclosure
author: pd-team & daffainfo & meme-lord author: pd-team & daffainfo & meme-lord
severity: low severity: low
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Ruby-on-Rails Database Configuration Exposure name: Ruby-on-Rails Database Configuration Exposure
author: pd-team author: pd-team
severity: low severity: low
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
author: geeknik author: geeknik
description: Redmine is a flexible project management web application written using Ruby on Rails framework - https://redmine.org/projects/redmine description: Redmine is a flexible project management web application written using Ruby on Rails framework - https://redmine.org/projects/redmine
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET
@ -16,9 +16,10 @@ requests:
- type: word - type: word
part: body part: body
words: words:
- adapter - 'adapter:'
- database - 'database:'
- host - 'host:'
- 'production:'
condition: and condition: and
- type: status - type: status

View File

@ -5,7 +5,7 @@ info:
author: pikpikcu author: pikpikcu
severity: high severity: high
reference: https://www.cnblogs.com/cHr1s/p/14499858.html reference: https://www.cnblogs.com/cHr1s/p/14499858.html
tags: ruijie,config tags: ruijie,config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Detect Private SSH and TLS Keys name: Detect Private SSH and TLS Keys
author: geeknik author: geeknik
severity: high severity: high
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: SFTP credentials exposure name: SFTP credentials exposure
author: sheikhrishad author: sheikhrishad
severity: medium severity: medium
tags: config,ftp tags: config,ftp,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: SymfonyProfiler information leakage name: SymfonyProfiler information leakage
author: wabafet author: wabafet
severity: medium severity: medium
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Symfony Database Configuration Exposure name: Symfony Database Configuration Exposure
author: pd-team author: pd-team
severity: high severity: high
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Symfony Profiler name: Symfony Profiler
author: pd-team author: pd-team
severity: high severity: high
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -3,7 +3,7 @@ info:
name: Web Config file name: Web Config file
author: Yash Anand @yashanand155 author: Yash Anand @yashanand155
severity: info severity: info
tags: config tags: config,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: X Prober server information leakage name: X Prober server information leakage
author: pdteam author: pdteam
severity: low severity: low
tags: config tags: config,exposures
reference: https://twitter.com/bugbounty_tips/status/1339984643517423616 reference: https://twitter.com/bugbounty_tips/status/1339984643517423616
requests: requests:

View File

@ -5,7 +5,7 @@ info:
author: oppsec author: oppsec
severity: info severity: info
description: Bower is a package manager which stores packages informations in bower.json file description: Bower is a package manager which stores packages informations in bower.json file
tags: file tags: file,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
author: gevakun author: gevakun
severity: low severity: low
reference: https://twitter.com/Wh11teW0lf/status/1295594085445709824 reference: https://twitter.com/Wh11teW0lf/status/1295594085445709824
tags: file tags: file,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Drupal Install name: Drupal Install
author: NkxxkN author: NkxxkN
severity: low severity: low
tags: file tags: file,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Directory Listing via DS_Store name: Directory Listing via DS_Store
author: 0w4ys author: 0w4ys
severity: info severity: info
tags: file tags: file,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Exposed Spring Data REST Application-Level Profile Semantics (ALPS) name: Exposed Spring Data REST Application-Level Profile Semantics (ALPS)
author: dwisiswant0 author: dwisiswant0
severity: medium severity: medium
tags: file tags: file,exposures
reference: https://niemand.com.ar/2021/01/08/exploiting-application-level-profile-semantics-apls-from-spring-data-rest/ reference: https://niemand.com.ar/2021/01/08/exploiting-application-level-profile-semantics-apls-from-spring-data-rest/
requests: requests:

View File

@ -4,7 +4,7 @@ info:
name: Filezilla name: Filezilla
author: amsda author: amsda
severity: medium severity: medium
tags: file tags: file,exposures
requests: requests:
- method: GET - method: GET

View File

@ -3,7 +3,7 @@ info:
name: Keycloak Json File name: Keycloak Json File
author: oppsec author: oppsec
severity: info severity: info
tags: file tags: file,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Lazy File Manager name: Lazy File Manager
author: amsda author: amsda
severity: medium severity: medium
tags: file tags: file,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: oppsec author: oppsec
severity: info severity: info
description: yarn.lock is a file which store all exactly versions of each dependency were installed. description: yarn.lock is a file which store all exactly versions of each dependency were installed.
tags: file tags: file,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: elmah.axd Disclosure name: elmah.axd Disclosure
author: shine author: shine
severity: medium severity: medium
tags: log tags: log,exposures
requests: requests:
- method: GET - method: GET

View File

@ -3,7 +3,7 @@ info:
name: common error log files name: common error log files
author: geeknik & daffainfo author: geeknik & daffainfo
severity: low severity: low
tags: log tags: log,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Laravel log file publicly accessible name: Laravel log file publicly accessible
author: sheikhrishad author: sheikhrishad
severity: low severity: low
tags: laravel,log tags: laravel,log,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Publicly accessible NPM Log file name: Publicly accessible NPM Log file
author: sheikhrishad author: sheikhrishad
severity: low severity: low
tags: npm,log tags: npm,log,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Rails Debug Mode Enabled name: Rails Debug Mode Enabled
author: pd-team author: pd-team
severity: medium severity: medium
tags: log,rails tags: log,rails,exposures
requests: requests:
- method: GET - method: GET

View File

@ -4,7 +4,7 @@ info:
name: Apache Struts setup in Debug-Mode name: Apache Struts setup in Debug-Mode
author: pd-team author: pd-team
severity: low severity: low
tags: log,struts,apache tags: log,struts,apache,exposures
requests: requests:
- method: GET - method: GET

View File

@ -5,7 +5,7 @@ info:
author: dhiyaneshDK author: dhiyaneshDK
severity: low severity: low
reference: https://www.rapid7.com/db/vulnerabilities/spider-asp-dot-net-trace-axd/ reference: https://www.rapid7.com/db/vulnerabilities/spider-asp-dot-net-trace-axd/
tags: log,asp tags: log,asp,exposures
requests: requests:
- method: GET - method: GET