From dc084d1b28c7ff6496543bf041105bf15d6ffe3f Mon Sep 17 00:00:00 2001 From: pussycat0x <65701233+pussycat0x@users.noreply.github.com> Date: Tue, 18 Jun 2024 15:49:03 +0530 Subject: [PATCH 1/3] Create mantisbt-anonymous-login.yaml --- .../mantisbt-anonymous-login.yaml | 31 +++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 http/default-logins/mantisbt-anonymous-login.yaml diff --git a/http/default-logins/mantisbt-anonymous-login.yaml b/http/default-logins/mantisbt-anonymous-login.yaml new file mode 100644 index 0000000000..818443dfef --- /dev/null +++ b/http/default-logins/mantisbt-anonymous-login.yaml @@ -0,0 +1,31 @@ +id: mantisbt-anonymous-login + +info: + name: mantisbt - Anonymous Login + author: pussycat0x + severity: medium + description: | + mantisbt Anonymous login were discovered. + metadata: + verified: true + max-request: 1 + shodan-query: http.favicon.hash:662709064 + tags: default-logins,anonymous,mantisbt,default-login + +http: + - method: GET + path: + - '{{BaseURL}}/my_view_page.php' + + matchers-condition: and + matchers: + - type: word + part: body + words: + - 'user-info">anonymous"' + - 'My View' + - 'Roadmap' + + - type: status + status: + - 200 From b6951c85dcf3f0f1183c8ce059be0bfdc8709a58 Mon Sep 17 00:00:00 2001 From: pussycat0x <65701233+pussycat0x@users.noreply.github.com> Date: Thu, 20 Jun 2024 17:32:53 +0530 Subject: [PATCH 2/3] Update mantisbt-anonymous-login.yaml --- http/default-logins/mantisbt-anonymous-login.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/http/default-logins/mantisbt-anonymous-login.yaml b/http/default-logins/mantisbt-anonymous-login.yaml index 818443dfef..e4627216de 100644 --- a/http/default-logins/mantisbt-anonymous-login.yaml +++ b/http/default-logins/mantisbt-anonymous-login.yaml @@ -25,6 +25,7 @@ http: - 'user-info">anonymous"' - 'My View' - 'Roadmap' + condition: and - type: status status: From a9be6082997c699e7f8300a65bfa38ab0bc5f54d Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Fri, 21 Jun 2024 11:04:45 +0530 Subject: [PATCH 3/3] Update and rename http/default-logins/mantisbt-anonymous-login.yaml to http/default-logins/mantisbt/mantisbt-anonymous-login.yaml --- .../default-logins/{ => mantisbt}/mantisbt-anonymous-login.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename http/default-logins/{ => mantisbt}/mantisbt-anonymous-login.yaml (96%) diff --git a/http/default-logins/mantisbt-anonymous-login.yaml b/http/default-logins/mantisbt/mantisbt-anonymous-login.yaml similarity index 96% rename from http/default-logins/mantisbt-anonymous-login.yaml rename to http/default-logins/mantisbt/mantisbt-anonymous-login.yaml index e4627216de..d8b07d134a 100644 --- a/http/default-logins/mantisbt-anonymous-login.yaml +++ b/http/default-logins/mantisbt/mantisbt-anonymous-login.yaml @@ -25,7 +25,7 @@ http: - 'user-info">anonymous"' - 'My View' - 'Roadmap' - condition: and + condition: and - type: status status: