From f5c2a8f539b28b3b959b4a697f18e2c8857cae38 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Thu, 1 Sep 2022 15:20:24 +0530 Subject: [PATCH 1/5] Create aem-debugging-libraries.yaml --- .../aem/aem-debugging-libraries.yaml | 44 +++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 misconfiguration/aem/aem-debugging-libraries.yaml diff --git a/misconfiguration/aem/aem-debugging-libraries.yaml b/misconfiguration/aem/aem-debugging-libraries.yaml new file mode 100644 index 0000000000..740884f192 --- /dev/null +++ b/misconfiguration/aem/aem-debugging-libraries.yaml @@ -0,0 +1,44 @@ +id: aem-debugging-libraries + +info: + name: Adobe AEM Debugging Client Libraries + author: dhiyaneshDk + severity: low + reference: + - https://aem4beginner.blogspot.com/debugging-client-libraries + - https://adobe-consulting-services.github.io/acs-aem-tools/features/dumplibs/index.html + metadata: + shodan-query: + - http.title:"AEM Sign In" + - http.component:"Adobe Experience Manager" + tags: misconfig,aem,adobe + +requests: + - method: GET + path: + - "{{BaseURL}}/libs/cq/ui/content/dumplibs.html" + - "{{BaseURL}}/libs/granite/ui/content/dumplibs.validate.html" + - "{{BaseURL}}/libs/granite/ui/content/dumplibs.rebuild.html" + - "{{BaseURL}}/libs/granite/ui/content/dumplibs.test.html" + - "{{BaseURL}}/libs/granite/ui/content/dumplibs.html" + + stop-at-first-match: true + matchers-condition: or + matchers: + - type: word + part: body + words: + - '"Client Libraries' + condition: or + + - type: word + part: body + words: + - 'Rebuild Client Libraries' + condition: or + + - type: word + part: body + words: + - 'Client Libraries Test Output' + condition: or From 8466f3f48b7ed9197059410c177f5d288156060e Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Thu, 1 Sep 2022 15:29:50 +0530 Subject: [PATCH 2/5] Update aem-debugging-libraries.yaml --- .../aem/aem-debugging-libraries.yaml | 20 +++++++------------ 1 file changed, 7 insertions(+), 13 deletions(-) diff --git a/misconfiguration/aem/aem-debugging-libraries.yaml b/misconfiguration/aem/aem-debugging-libraries.yaml index 740884f192..ba6b395428 100644 --- a/misconfiguration/aem/aem-debugging-libraries.yaml +++ b/misconfiguration/aem/aem-debugging-libraries.yaml @@ -17,28 +17,22 @@ requests: - method: GET path: - "{{BaseURL}}/libs/cq/ui/content/dumplibs.html" - - "{{BaseURL}}/libs/granite/ui/content/dumplibs.validate.html" - - "{{BaseURL}}/libs/granite/ui/content/dumplibs.rebuild.html" - - "{{BaseURL}}/libs/granite/ui/content/dumplibs.test.html" - "{{BaseURL}}/libs/granite/ui/content/dumplibs.html" stop-at-first-match: true - matchers-condition: or + matchers-condition: and matchers: - type: word part: body words: - '"Client Libraries' - condition: or + condition: and - type: word - part: body + part: header words: - - 'Rebuild Client Libraries' - condition: or + - text/html - - type: word - part: body - words: - - 'Client Libraries Test Output' - condition: or + - type: status + status: + - 200 From 235e42bb62ab597030cac5feba87f81dc9132577 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Thu, 1 Sep 2022 15:33:27 +0530 Subject: [PATCH 3/5] Update aem-debugging-libraries.yaml --- .../aem/aem-debugging-libraries.yaml | 20 ++++++++++++------- 1 file changed, 13 insertions(+), 7 deletions(-) diff --git a/misconfiguration/aem/aem-debugging-libraries.yaml b/misconfiguration/aem/aem-debugging-libraries.yaml index ba6b395428..740884f192 100644 --- a/misconfiguration/aem/aem-debugging-libraries.yaml +++ b/misconfiguration/aem/aem-debugging-libraries.yaml @@ -17,22 +17,28 @@ requests: - method: GET path: - "{{BaseURL}}/libs/cq/ui/content/dumplibs.html" + - "{{BaseURL}}/libs/granite/ui/content/dumplibs.validate.html" + - "{{BaseURL}}/libs/granite/ui/content/dumplibs.rebuild.html" + - "{{BaseURL}}/libs/granite/ui/content/dumplibs.test.html" - "{{BaseURL}}/libs/granite/ui/content/dumplibs.html" stop-at-first-match: true - matchers-condition: and + matchers-condition: or matchers: - type: word part: body words: - '"Client Libraries' - condition: and + condition: or - type: word - part: header + part: body words: - - text/html + - 'Rebuild Client Libraries' + condition: or - - type: status - status: - - 200 + - type: word + part: body + words: + - 'Client Libraries Test Output' + condition: or From 3ae3167b4eab9df687fb2accfc5c8162544c2f9d Mon Sep 17 00:00:00 2001 From: Ritik Chaddha <44563978+ritikchaddha@users.noreply.github.com> Date: Thu, 1 Sep 2022 15:34:49 +0530 Subject: [PATCH 4/5] Update aem-debugging-libraries.yaml --- misconfiguration/aem/aem-debugging-libraries.yaml | 14 ++------------ 1 file changed, 2 insertions(+), 12 deletions(-) diff --git a/misconfiguration/aem/aem-debugging-libraries.yaml b/misconfiguration/aem/aem-debugging-libraries.yaml index 740884f192..70f78073ef 100644 --- a/misconfiguration/aem/aem-debugging-libraries.yaml +++ b/misconfiguration/aem/aem-debugging-libraries.yaml @@ -8,6 +8,7 @@ info: - https://aem4beginner.blogspot.com/debugging-client-libraries - https://adobe-consulting-services.github.io/acs-aem-tools/features/dumplibs/index.html metadata: + verified: true shodan-query: - http.title:"AEM Sign In" - http.component:"Adobe Experience Manager" @@ -23,22 +24,11 @@ requests: - "{{BaseURL}}/libs/granite/ui/content/dumplibs.html" stop-at-first-match: true - matchers-condition: or matchers: - type: word part: body words: - - '"Client Libraries' - condition: or - - - type: word - part: body - words: + - 'Client Libraries' - 'Rebuild Client Libraries' - condition: or - - - type: word - part: body - words: - 'Client Libraries Test Output' condition: or From 3204b0bc35eeb43a217ad148ad0b59892552c659 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Thu, 1 Sep 2022 16:41:19 +0530 Subject: [PATCH 5/5] Update aem-debugging-libraries.yaml --- misconfiguration/aem/aem-debugging-libraries.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/misconfiguration/aem/aem-debugging-libraries.yaml b/misconfiguration/aem/aem-debugging-libraries.yaml index 70f78073ef..75df6518a5 100644 --- a/misconfiguration/aem/aem-debugging-libraries.yaml +++ b/misconfiguration/aem/aem-debugging-libraries.yaml @@ -3,7 +3,7 @@ id: aem-debugging-libraries info: name: Adobe AEM Debugging Client Libraries author: dhiyaneshDk - severity: low + severity: info reference: - https://aem4beginner.blogspot.com/debugging-client-libraries - https://adobe-consulting-services.github.io/acs-aem-tools/features/dumplibs/index.html