Update elmah-log-file.yaml

patch-1
Ritik Chaddha 2022-11-24 16:05:00 +05:30 committed by GitHub
parent 00ab7ec92b
commit 66d0ae1a6f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 5 additions and 4 deletions

View File

@ -1,7 +1,7 @@
id: elmah-log-file
info:
name: elmah.axd Disclosure
name: ELMAH Exposure
author: shine,idealphase
severity: medium
description: |
@ -9,20 +9,21 @@ info:
reference:
- https://code.google.com/archive/p/elmah/
- https://www.troyhunt.com/aspnet-session-hijacking-with-google/
tags: logs,exposure
metadata:
verified: true
tags: logs,elmah,exposure
requests:
- method: GET
path:
- "{{BaseURL}}/elmah.axd"
- "{{BaseURL}}/elmah"
- "{{BaseURL}}/elmah.axd"
stop-at-first-match: true
host-redirects: true
max-redirects: 2
matchers-condition: and
matchers:
- type: word
words:
- 'Error Log for'