From 79a78622cee629208e91c6ab841cc242d5d5cea0 Mon Sep 17 00:00:00 2001 From: Ritik Chaddha <44563978+ritikchaddha@users.noreply.github.com> Date: Fri, 28 Jun 2024 17:51:15 +0530 Subject: [PATCH 1/2] Create caprover-default-login.yaml --- .../caprover-default-login.yaml | 34 +++++++++++++++++++ 1 file changed, 34 insertions(+) create mode 100644 http/default-logins/caprover-default-login.yaml diff --git a/http/default-logins/caprover-default-login.yaml b/http/default-logins/caprover-default-login.yaml new file mode 100644 index 0000000000..710c0bfde9 --- /dev/null +++ b/http/default-logins/caprover-default-login.yaml @@ -0,0 +1,34 @@ +id: caprover-default-login + +info: + name: Caprover - Default Login + author: ritikchaddha + severity: high + description: | + Caprover defaultl login has been detected. + metadata: + verified: true + max-request: 2 + shodan-query: http.favicon.hash:988422585 + tags: caprover,default-login,misconfig + +variables: + password: captain42 + +http: + - raw: + - | + POST /api/v2/login HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/json + x-namespace: captain + + {"password":"{{password}}"} + + matchers: + - type: dsl + dsl: + - 'contains_all(body, "status\":100", "Login succeeded", "token\":")' + - 'contains(header, "application/json")' + - 'status_code == 200' + condition: and From cb5e8e0ff49da46869194e5a9724c22546fe863d Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Fri, 28 Jun 2024 17:56:08 +0530 Subject: [PATCH 2/2] minor update --- http/default-logins/{ => caprover}/caprover-default-login.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename http/default-logins/{ => caprover}/caprover-default-login.yaml (97%) diff --git a/http/default-logins/caprover-default-login.yaml b/http/default-logins/caprover/caprover-default-login.yaml similarity index 97% rename from http/default-logins/caprover-default-login.yaml rename to http/default-logins/caprover/caprover-default-login.yaml index 710c0bfde9..9fc70b65fa 100644 --- a/http/default-logins/caprover-default-login.yaml +++ b/http/default-logins/caprover/caprover-default-login.yaml @@ -8,7 +8,7 @@ info: Caprover defaultl login has been detected. metadata: verified: true - max-request: 2 + max-request: 1 shodan-query: http.favicon.hash:988422585 tags: caprover,default-login,misconfig