updated matchers & info

patch-1
Ritik Chaddha 2023-03-30 22:02:48 +05:30 committed by GitHub
parent 2cfda68ec9
commit 768df93e3d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 9 additions and 7 deletions

View File

@ -1,15 +1,16 @@
id: arcgis-tokens
id: arcgis-token-service
info:
name: ArcGIS Tokens
name: ArcGIS Token Service - Detect
author: HeeresS
severity: info
description: Check for the existence of the "/arcgis/tokens/" path on an ArcGIS server.
description: Check for the existence of the ArcGIS Token Service on an ArcGIS server.
reference:
- https://enterprise.arcgis.com/en/
classification:
cwe-id: CWE-1270
tags: arcgis, tokens, security
metadata:
verified: "true"
shodan-query: title:"ArcGIS"
tags: panel,arcgis,tokens,detect
requests:
- method: GET
@ -19,8 +20,9 @@ requests:
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'tokens'
- 'alt="ArcGIS Token Service'
- type: status
status: