From a1564dfc12ead2e6edb084fd3fb4150f17449f11 Mon Sep 17 00:00:00 2001 From: Dominique RIGHETTO Date: Sat, 14 Sep 2024 08:41:47 +0200 Subject: [PATCH] Update gitea-detect.yaml --- http/technologies/gitea-detect.yaml | 20 ++++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) diff --git a/http/technologies/gitea-detect.yaml b/http/technologies/gitea-detect.yaml index 7d3e745f39..061a02a97f 100644 --- a/http/technologies/gitea-detect.yaml +++ b/http/technologies/gitea-detect.yaml @@ -2,26 +2,31 @@ id: gitea-detect info: name: Gitea Detect - author: pikpikcu + author: pikpikcu,righettod severity: info + description: Gitea was detected. + reference: + - https://about.gitea.com/ + - https://docs.gitea.com/api metadata: - max-request: 2 + verified: true + max-request: 1 + shodan-query: http.title:"Gitea" tags: tech,gitea http: - method: GET path: - - "{{BaseURL}}" - "{{BaseURL}}/user/login" - stop-at-first-match: true - matchers-condition: and matchers: - type: word part: body words: - "Powered by Gitea" + - 'content="Gitea' + condition: or - type: status status: @@ -30,6 +35,9 @@ http: extractors: - type: regex part: body + group: 1 regex: - "Powered by Gitea(\\s*)Version:(\\s*)([\\d.]+)" -# digest: 490a004630440220791687a21e5f46c7a6eb923d809d18340770e0c193af81f0a9934a3f199169780220280ffe146a31762152e070e81bffa10978320384487251c5643d87884f18867e:922c64590222798bb761d5b6d8e72950 \ No newline at end of file + - "Gitea Version: ([0-9a-z+-.~]+)" + - 'theme-gitea-auto.css\?v=([0-9a-z+-.~]+)' + - 'encodeURIComponent.{2}([0-9a-z+-.~]+).{2}'