diff --git a/http/exposures/configs/apache-ozone-conf.yaml b/http/exposures/configs/apache-ozone-conf.yaml new file mode 100644 index 0000000000..5c80a56ec3 --- /dev/null +++ b/http/exposures/configs/apache-ozone-conf.yaml @@ -0,0 +1,32 @@ +id: apache-ozone-conf + +info: + name: Apache Ozone - Exposure + author: icarot + severity: info + description: | + Detects if path /conf of Apache Ozone web application is exposed. + classification: + cpe: cpe:2.3:a:apache:ozone:-:*:*:*:*:*:*:* + metadata: + max-request: 1 + vendor: apache + product: ozone + shodan-query: title:"Apache Ozone" + tags: tech,ozone,apache,detect + +http: + - method: GET + path: + - "{{BaseURL}}/conf" + + matchers-condition: and + matchers: + - type: word + words: + - 'ozone-default.xml' + - 'ozone' + + - type: status + status: + - 200