diff --git a/security-misconfiguration/trace.axd-detect.yaml b/security-misconfiguration/trace.axd-detect.yaml new file mode 100644 index 0000000000..5a813ca2a0 --- /dev/null +++ b/security-misconfiguration/trace.axd-detect.yaml @@ -0,0 +1,24 @@ +id: trace.axd-detect + +info: + name: ASP.NET Trace.AXD Information Leak + author: dhiyaneshDK + severity: low + reference: https://www.rapid7.com/db/vulnerabilities/spider-asp-dot-net-trace-axd/ + + +requests: + - method: GET + path: + - "{{BaseURL}}/Trace.axd" + + matchers-condition: and + matchers: + - type: word + words: + -

Application Trace

+ condition: and + + - type: status + status: + - 200