From 235f91a3f9a6ae41be03a2828595983c53bcb010 Mon Sep 17 00:00:00 2001 From: Dominique RIGHETTO Date: Wed, 1 Nov 2023 19:14:30 +0100 Subject: [PATCH 1/2] Add files via upload --- http/exposed-panels/servicenow-panel.yaml | 42 +++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 http/exposed-panels/servicenow-panel.yaml diff --git a/http/exposed-panels/servicenow-panel.yaml b/http/exposed-panels/servicenow-panel.yaml new file mode 100644 index 0000000000..7a5c24a342 --- /dev/null +++ b/http/exposed-panels/servicenow-panel.yaml @@ -0,0 +1,42 @@ +id: servicenow-panel + +info: + name: ServiceNow Login Panel - Detect + author: righettod + severity: info + description: | + Service Now Login Panel was detected. + reference: + - https://www.servicenow.com/ + metadata: + verified: true + max-request: 1 + shodan-query: http.favicon.hash:1701804003 + tags: panel,servicenow,login,detect + +http: + - method: GET + path: + - '{{BaseURL}}/login.do' + + matchers-condition: and + matchers: + - type: word + part: body + words: + - 'ServiceNow' + - 'window.NOW.' + - 'NOW.user.userID' + condition: and + case-insensitive: true + + - type: status + status: + - 200 + + extractors: + - type: regex + part: body + group: 1 + regex: + - '(?i)g_builddate\s+=\s+"([0-9._-]+)"' From 88ff778036b2c8e6474b16f8292adc255c8e3a30 Mon Sep 17 00:00:00 2001 From: Dominique RIGHETTO Date: Wed, 1 Nov 2023 19:25:01 +0100 Subject: [PATCH 2/2] Fix typo --- http/exposed-panels/servicenow-panel.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/http/exposed-panels/servicenow-panel.yaml b/http/exposed-panels/servicenow-panel.yaml index 7a5c24a342..8cbaead76b 100644 --- a/http/exposed-panels/servicenow-panel.yaml +++ b/http/exposed-panels/servicenow-panel.yaml @@ -5,7 +5,7 @@ info: author: righettod severity: info description: | - Service Now Login Panel was detected. + ServiceNow Login Panel was detected. reference: - https://www.servicenow.com/ metadata: