From 55b6b33e93cf5d65c5cf853fecc1d945c6627efc Mon Sep 17 00:00:00 2001 From: sandeep <8293321+bauthard@users.noreply.github.com> Date: Mon, 15 Feb 2021 21:29:12 +0530 Subject: [PATCH] misc changes --- .../{other => samsung}/samsung-wlan-ap-lfi.yaml | 1 + .../{other => samsung}/samsung-wlan-ap-rce.yaml | 1 + .../{other => samsung}/samsung-wlan-ap-xss.yaml | 8 +++++++- workflows/samsung-wlan-ap-workflow.yaml | 6 +++--- 4 files changed, 12 insertions(+), 4 deletions(-) rename vulnerabilities/{other => samsung}/samsung-wlan-ap-lfi.yaml (95%) rename vulnerabilities/{other => samsung}/samsung-wlan-ap-rce.yaml (95%) rename vulnerabilities/{other => samsung}/samsung-wlan-ap-xss.yaml (83%) diff --git a/vulnerabilities/other/samsung-wlan-ap-lfi.yaml b/vulnerabilities/samsung/samsung-wlan-ap-lfi.yaml similarity index 95% rename from vulnerabilities/other/samsung-wlan-ap-lfi.yaml rename to vulnerabilities/samsung/samsung-wlan-ap-lfi.yaml index 8e205a7a17..7194cb591b 100644 --- a/vulnerabilities/other/samsung-wlan-ap-lfi.yaml +++ b/vulnerabilities/samsung/samsung-wlan-ap-lfi.yaml @@ -5,6 +5,7 @@ info: author: pikpikcu severity: critical reference: https://iryl.info/2020/11/27/exploiting-samsung-router-wlan-ap-wea453e/ + tags: xss,samsung,lfi requests: - method: GET diff --git a/vulnerabilities/other/samsung-wlan-ap-rce.yaml b/vulnerabilities/samsung/samsung-wlan-ap-rce.yaml similarity index 95% rename from vulnerabilities/other/samsung-wlan-ap-rce.yaml rename to vulnerabilities/samsung/samsung-wlan-ap-rce.yaml index 7a9c40e2af..e39424359d 100644 --- a/vulnerabilities/other/samsung-wlan-ap-rce.yaml +++ b/vulnerabilities/samsung/samsung-wlan-ap-rce.yaml @@ -5,6 +5,7 @@ info: author: pikpikcu severity: critical reference: https://iryl.info/2020/11/27/exploiting-samsung-router-wlan-ap-wea453e/ + tags: xss,samsung,rce requests: - method: POST diff --git a/vulnerabilities/other/samsung-wlan-ap-xss.yaml b/vulnerabilities/samsung/samsung-wlan-ap-xss.yaml similarity index 83% rename from vulnerabilities/other/samsung-wlan-ap-xss.yaml rename to vulnerabilities/samsung/samsung-wlan-ap-xss.yaml index 1ef36b8774..bf1fbf958a 100644 --- a/vulnerabilities/other/samsung-wlan-ap-xss.yaml +++ b/vulnerabilities/samsung/samsung-wlan-ap-xss.yaml @@ -5,7 +5,7 @@ info: author: pikpikcu severity: medium reference: https://iryl.info/2020/11/27/exploiting-samsung-router-wlan-ap-wea453e/ - + tags: xss,samsung,xss requests: - method: GET path: @@ -17,6 +17,12 @@ requests: words: - "/tmp/www/" part: body + - type: status status: - 404 + + - type: word + words: + - "text/html" + part: header \ No newline at end of file diff --git a/workflows/samsung-wlan-ap-workflow.yaml b/workflows/samsung-wlan-ap-workflow.yaml index 3997009336..6216c25d63 100644 --- a/workflows/samsung-wlan-ap-workflow.yaml +++ b/workflows/samsung-wlan-ap-workflow.yaml @@ -10,6 +10,6 @@ workflows: - template: default-logins/samsung/samsung-wlan-ap-default-credentials.yaml subtemplates: - - template: vulnerabilities/other/samsung-wlan-ap-rce.yaml - - template: vulnerabilities/other/samsung-wlan-ap-lfi.yaml - - template: vulnerabilities/other/samsung-wlan-ap-xss.yaml + - template: vulnerabilities/samsung/samsung-wlan-ap-rce.yaml + - template: vulnerabilities/samsung/samsung-wlan-ap-lfi.yaml + - template: vulnerabilities/samsung/samsung-wlan-ap-xss.yaml