From bdc5bfc500b55f7edd5e3c5ebe7326569475fd97 Mon Sep 17 00:00:00 2001 From: sandeep <8293321+ehsandeep@users.noreply.github.com> Date: Wed, 26 Jul 2023 22:15:17 +0530 Subject: [PATCH 1/2] Added MobileIron Sentry Panel detection --- http/exposed-panels/mobileiron-sentry.yaml | 29 ++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 http/exposed-panels/mobileiron-sentry.yaml diff --git a/http/exposed-panels/mobileiron-sentry.yaml b/http/exposed-panels/mobileiron-sentry.yaml new file mode 100644 index 0000000000..324a89a7bf --- /dev/null +++ b/http/exposed-panels/mobileiron-sentry.yaml @@ -0,0 +1,29 @@ +id: mobileiron-sentry + +info: + name: MobileIron Sentry Panel + author: pdteam + severity: info + description: MobileIron Sentry panel was detected. + reference: + - https://help.ivanti.com/mi/help/en_us/sntry/9.9.0/gdcl/Content/SentryGuide/MobileIron_Sentry_overvi.htm + metadata: + max-request: 1 + shodan-query: http.favicon.hash:967636089 + tags: panel,mobileiron + +http: + - method: GET + path: + - "{{BaseURL}}/mics/login.jsp" + + matchers: + - type: word + words: + - "MobileIron System Manager" + + extractors: + - type: regex + group: 1 + regex: + - \?([\d.]+)" \ No newline at end of file From 7ae2fdc1150fcf667ede16fd07f9290f6aa5c56b Mon Sep 17 00:00:00 2001 From: pussycat0x <65701233+pussycat0x@users.noreply.github.com> Date: Thu, 27 Jul 2023 10:48:52 +0530 Subject: [PATCH 2/2] Update mobileiron-sentry.yaml --- http/exposed-panels/mobileiron-sentry.yaml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/http/exposed-panels/mobileiron-sentry.yaml b/http/exposed-panels/mobileiron-sentry.yaml index 324a89a7bf..9e7f108aa1 100644 --- a/http/exposed-panels/mobileiron-sentry.yaml +++ b/http/exposed-panels/mobileiron-sentry.yaml @@ -1,7 +1,7 @@ id: mobileiron-sentry info: - name: MobileIron Sentry Panel + name: MobileIron Sentry Panel - Detect author: pdteam severity: info description: MobileIron Sentry panel was detected. @@ -9,6 +9,7 @@ info: - https://help.ivanti.com/mi/help/en_us/sntry/9.9.0/gdcl/Content/SentryGuide/MobileIron_Sentry_overvi.htm metadata: max-request: 1 + verified: true shodan-query: http.favicon.hash:967636089 tags: panel,mobileiron @@ -26,4 +27,4 @@ http: - type: regex group: 1 regex: - - \?([\d.]+)" \ No newline at end of file + - \?([\d.]+)"