fix template

patch-1
Dhiyaneshwaran 2023-07-21 18:27:11 +05:30 committed by GitHub
parent 8eb5b8e206
commit c3c5984893
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 23 additions and 2 deletions

View File

@ -1,12 +1,22 @@
id: swagger-api
info:
name: Public Swagger API
name: Public Swagger API - Detect
author: pdteam,c-sh0
severity: info
description: Public Swagger API was detected.
reference: https://swagger.io/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cvss-score: 0.0
cwe-id: CWE-200
metadata:
max-request: 53
verified: true
shodan-query: http.title:"swagger"
tags: exposure,api,swagger
requests:
http:
- method: GET
path:
- "{{BaseURL}}/swagger-ui/swagger-ui.js"
@ -26,6 +36,7 @@ requests:
- "{{BaseURL}}/swagger/v1/swagger.json"
- "{{BaseURL}}/swagger/v1/swagger.yaml"
- "{{BaseURL}}/api/index.html"
- "{{BaseURL}}/api/doc"
- "{{BaseURL}}/api/docs/"
- "{{BaseURL}}/api/swagger.json"
- "{{BaseURL}}/api/swagger.yaml"
@ -39,6 +50,7 @@ requests:
- "{{BaseURL}}/api/apidocs/swagger.json"
- "{{BaseURL}}/api/apidocs/swagger.yaml"
- "{{BaseURL}}/api/swagger-ui/api-docs"
- "{{BaseURL}}/api/doc.json"
- "{{BaseURL}}/api/api-docs"
- "{{BaseURL}}/api/apidocs"
- "{{BaseURL}}/api/swagger"
@ -56,8 +68,15 @@ requests:
- "{{BaseURL}}/api/v1/swagger-ui/swagger.yaml"
- "{{BaseURL}}/swagger-resources/restservices/v2/api-docs"
- "{{BaseURL}}/api/swagger_doc.json"
- "{{BaseURL}}/docu"
- "{{BaseURL}}/docs"
- "{{BaseURL}}/swagger"
- "{{BaseURL}}/api-doc"
- "{{BaseURL}}/doc/"
headers:
Accept: text/html
stop-at-first-match: true
matchers-condition: and
matchers:
@ -67,7 +86,9 @@ requests:
- "Swagger 2.0"
- "\"swagger\":"
- "Swagger UI"
- "loadSwaggerUI"
- "**token**:"
- "id=\"swagger-ui"
condition: or
- type: status