diff --git a/exposed-panels/3cx-phone-management-panel.yaml b/exposed-panels/3cx-phone-management-panel.yaml new file mode 100644 index 0000000000..1d7a536697 --- /dev/null +++ b/exposed-panels/3cx-phone-management-panel.yaml @@ -0,0 +1,28 @@ +id: 3cx-phone-management-panel + +info: + name: 3CX Phone System Management Console Detect + author: idealphase + severity: info + reference: + - https://www.3cx.com/ + - https://www.3cx.com/phone-system/ + - https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88 + metadata: + shodan-query: + - http.title:"3CX Phone System Management Console" + - http.favicon.hash:970132176 + google-query: intitle:"3CX Phone System Management Console" + tags: panel,3cx + +requests: + - method: GET + path: + - '{{BaseURL}}' + + matchers: + - type: word + words: + - "3CX Phone System Management Console" + - "Welcome to the 3CX Management Console" + condition: or diff --git a/exposed-panels/3cx-phone-webclient-management-panel.yaml b/exposed-panels/3cx-phone-webclient-management-panel.yaml new file mode 100644 index 0000000000..1c4be16616 --- /dev/null +++ b/exposed-panels/3cx-phone-webclient-management-panel.yaml @@ -0,0 +1,26 @@ +id: 3cx-phone-webclient-management-panel + +info: + name: 3CX Phone System Webclient Management Console + author: idealphase + severity: info + reference: + - https://www.3cx.com/phone-system/ + - https://www.3cx.com/blog/unified-communications/client-apps/ + - https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88 + metadata: + shodan-query: http.title:"3CX Webclient" + google-query: intitle:"3CX Webclient" + tags: panel,3cx + +requests: + - method: GET + path: + - '{{BaseURL}}/webclient/' + + matchers: + - type: word + words: + - "