From 9cd21c72b8f05fd0fbbe3579e7de37c918dcf0e9 Mon Sep 17 00:00:00 2001 From: sandeep <8293321+ehsandeep@users.noreply.github.com> Date: Mon, 31 May 2021 12:28:19 +0530 Subject: [PATCH] Added exposed-vscode --- exposures/configs/exposed-vscode.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 exposures/configs/exposed-vscode.yaml diff --git a/exposures/configs/exposed-vscode.yaml b/exposures/configs/exposed-vscode.yaml new file mode 100644 index 0000000000..6bc6c6661d --- /dev/null +++ b/exposures/configs/exposed-vscode.yaml @@ -0,0 +1,18 @@ +id: exposed-vscode + +info: + name: Exposed VSCode Folders + author: aashiq + severity: low + description: Searches for exposed Visual Studio Code Directories by querying the /.vscode endpoint and existence of "index of" in the body + tags: vscode,exposure + +requests: + - method: GET + path: + - "{{BaseURL}}/.vscode/" + matchers: + - type: word + words: + - "Index of /.vscode" + part: body \ No newline at end of file