add rabbitmq default password detection
parent
2499aaa0a6
commit
941ab6d875
|
@ -0,0 +1,16 @@
|
|||
id: rabbitmq-dashboard
|
||||
|
||||
info:
|
||||
name: RabbitMQ Dashboard
|
||||
author: fyoorer
|
||||
severity: informative
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
path:
|
||||
- '{{BaseURL}}'
|
||||
matchers:
|
||||
- type: word
|
||||
words:
|
||||
- "RabbitMQ Management"
|
||||
part: body
|
|
@ -0,0 +1,17 @@
|
|||
id: rabbitmq-default-admin
|
||||
|
||||
info:
|
||||
name: RabbitMQ Default Credentials
|
||||
author: fyoorer
|
||||
severity: High
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
headers:
|
||||
authorization: "Basic Z3Vlc3Q6Z3Vlc3Q="
|
||||
path:
|
||||
- "{{BaseURL}}/api/whoami"
|
||||
matchers:
|
||||
- type: status
|
||||
status:
|
||||
- 200
|
|
@ -0,0 +1,15 @@
|
|||
id: rabbitmq-workflow
|
||||
|
||||
info:
|
||||
name: RabbitMQ Workflow
|
||||
author: fyoorer
|
||||
|
||||
variables:
|
||||
rabbitmq-dashboard: panels/rabbitmq-dashboard.yaml
|
||||
rabbitmq-default-admin: security-misconfiguration/rabbitmq-default-admin.yaml
|
||||
|
||||
logic:
|
||||
|
|
||||
if rabbitmq-dashboard() {
|
||||
rabbitmq-default-admin()
|
||||
}
|
Loading…
Reference in New Issue