diff --git a/tokens/unecrypted-bigip-ltm-cookie.yaml b/tokens/unecrypted-bigip-ltm-cookie.yaml new file mode 100644 index 0000000000..dcf00fb655 --- /dev/null +++ b/tokens/unecrypted-bigip-ltm-cookie.yaml @@ -0,0 +1,18 @@ +id: unecrypted-bigip-ltm-cookie + +info: + name: F5 BIGIP Unecrypted Cookie + author: PR3R00T + severity: low + +requests: + - method: GET + path: + - "{{BaseURL}}" + redirects: true + matchers: + - type: regex + regex: + - '(BIGipServer[a-z\_\.\-\~0-9A-Z]*)=([0-9a-zA-Z\.]*;)' + - '=[0-9]*\.[0-9]{3,5}\.[0-9]{4};' + part: header