From 644cc91b61f02bd049f86c00175cb8db38f2ebb5 Mon Sep 17 00:00:00 2001 From: Dominique RIGHETTO Date: Wed, 29 May 2024 19:24:43 +0200 Subject: [PATCH] Add files via upload --- .../oracle-access-management.yaml | 40 +++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 http/exposed-panels/oracle-access-management.yaml diff --git a/http/exposed-panels/oracle-access-management.yaml b/http/exposed-panels/oracle-access-management.yaml new file mode 100644 index 0000000000..5916c37753 --- /dev/null +++ b/http/exposed-panels/oracle-access-management.yaml @@ -0,0 +1,40 @@ +id: oracle-access-management + +info: + name: Oracle Access Management Login Panel - Detect + author: righettod + severity: info + description: Oracle Access Management login panel was detected. + classification: + cpe: cpe:2.3:a:oracle:access_manager:*:*:*:*:*:*:*:* + metadata: + max-request: 1 + shodan-query: http.title:"Oracle Access Management" + vendor: oracle + verified: true + tags: panel,oracle,login,detect + +http: + - method: GET + path: + - "{{BaseURL}}/oam/pages/login.jsp" + + matchers-condition: and + matchers: + - type: word + part: body + words: + - "Login - Oracle Access Management" + - "/oam/server/auth_cred_submit" + condition: or + + - type: status + status: + - 200 + + extractors: + - type: regex + part: body + group: 1 + regex: + - '(?i)Login\s+-\s+Oracle\s+Access\s+Management\s+([a-z0-9]+)' \ No newline at end of file