diff --git a/default-logins/minio/minio-default-password.yaml b/default-logins/minio/minio-default-password.yaml new file mode 100644 index 0000000000..7d2b90fde6 --- /dev/null +++ b/default-logins/minio/minio-default-password.yaml @@ -0,0 +1,41 @@ +id: minio-default-password + +info: + name: Minio Default Password + author: pikpikcu + severity: medium + +requests: + - method: POST + path: + - "{{BaseURL}}/minio/webrpc" + headers: + Content-Type: application/json + body: | + {"id":1,"jsonrpc":"2.0","params":{"username":"minioadmin","password":"minioadmin"},"method":"Web.Login"} + + - method: POST + path: + - "{{BaseURL}}/minio/webrpc" + headers: + Content-Type: application/json + body: | + {"id":1,"jsonrpc":"2.0","params":{"username":"minioadmin","password":"minioadmin"},"method":"web.Login"} + matchers-condition: and + matchers: + + - type: word + words: + - "Content-Type: application/json" + part: header + + - type: word + words: + - 'uiVersion' + - 'token' + part: body + condition: and + + - type: status + status: + - 200