Create glpi-directory-listing.yaml (#3439)

* Create glpi-directory-listing.yaml

* Linting

* Linting

Adds ``part: header``

* Update glpi-directory-listing.yaml

* Update glpi-directory-listing.yaml

* Update glpi-directory-listing.yaml

* Update glpi-directory-listing.yaml

* Update glpi-directory-listing.yaml

* Update glpi-directory-listing.yaml

* Update glpi-directory-listing.yaml

Co-authored-by: Sandeep Singh <sandeep@projectdiscovery.io>
Co-authored-by: Prince Chaddha <prince@projectdiscovery.io>
patch-1
ImNightmaree 2021-12-30 08:35:45 +00:00 committed by GitHub
parent 99741d1e5f
commit 9923e91348
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 30 additions and 0 deletions

View File

@ -0,0 +1,30 @@
id: glpi-directory-listing
info:
name: GLPI Directory Listing
author: RedTeamBrasil,ImNightmaree
description: In certain cases, system administrators leave directory listing enabled which can sometimes expose sensitive files.
severity: low
tags: glpi,misconfig
requests:
- raw:
- |
GET {{expose_data}} HTTP/1.1
Host: {{Hostname}}
payloads:
expose_data:
- /glpi/files/
- /glpi/
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Index of /glpi/"
- type: status
status:
- 200