diff --git a/http/exposed-panels/bmc/bmc-remedy-sso-panel.yaml b/http/exposed-panels/bmc/bmc-remedy-sso-panel.yaml new file mode 100644 index 0000000000..c3edbe9dd4 --- /dev/null +++ b/http/exposed-panels/bmc/bmc-remedy-sso-panel.yaml @@ -0,0 +1,30 @@ +id: bmc-remedy-sso-panel + +info: + name: BMC Remedy SSO Login Panel - Detect + author: righettod + severity: info + description: | + BMC Remedy Single Sign-On domain data entry login panel was detected. + reference: + - https://www.bmc.com/it-solutions/remedy-itsm.html + metadata: + verified: true + max-request: 2 + shodan-query: http.title:"BMC Remedy Single Sign-On domain data entry" + tags: panel,bmc,login,detect + +http: + - method: GET + path: + - "{{BaseURL}}/arsys/" + - "{{BaseURL}}/webUI/userHome.do" + + stop-at-first-match: true + + matchers: + - type: dsl + dsl: + - 'status_code == 200' + - 'contains(to_lower(body), "