From 6c64c42dc024a707b2981f40bb07fbbd4598b39c Mon Sep 17 00:00:00 2001 From: sandeep Date: Sat, 13 Nov 2021 22:14:58 +0530 Subject: [PATCH] misc updates --- default-logins/pentaho/pentaho-default-login.yaml | 3 ++- network/samba-detect.yaml | 5 ++++- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/default-logins/pentaho/pentaho-default-login.yaml b/default-logins/pentaho/pentaho-default-login.yaml index 0963f688ac..a91dfc9bd8 100644 --- a/default-logins/pentaho/pentaho-default-login.yaml +++ b/default-logins/pentaho/pentaho-default-login.yaml @@ -5,7 +5,7 @@ info: author: pussycat0x severity: high metadata: - shodan-query: 'pentaho' + shodan-query: pentaho tags: pentaho,default-login requests: @@ -14,6 +14,7 @@ requests: POST /pentaho/j_spring_security_check HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded; charset=UTF-8 + j_username={{user}}&j_password={{pass}} attack: pitchfork diff --git a/network/samba-detect.yaml b/network/samba-detect.yaml index 76a3baaf40..1dd94f2eda 100644 --- a/network/samba-detect.yaml +++ b/network/samba-detect.yaml @@ -1,16 +1,19 @@ id: samba-detection + info: name: samba detection author: pussycat0x severity: info - tags: network,smb, samba + tags: network,smb,samba network: - inputs: - data: 000000a4ff534d4272000000000801400000000000000000000000000000400600000100008100025043204e4554574f524b2050524f4752414d20312e3000024d4943524f534f4654204e4554574f524b5320312e303300024d4943524f534f4654204e4554574f524b5320332e3000024c414e4d414e312e3000024c4d312e3258303032000253616d626100024e54204c414e4d414e20312e3000024e54204c4d20302e313200 type: hex + host: - "{{Hostname}}" - "{{Hostname}}:139" + matchers: - type: word words: