From c6b036ffb9c9580fa4da12170a10de7ef9a0945d Mon Sep 17 00:00:00 2001 From: Ritik Chaddha <44563978+ritikchaddha@users.noreply.github.com> Date: Mon, 10 Jul 2023 18:17:56 +0530 Subject: [PATCH] updated name,info,matcher --- .../{d-link-auth-bypass.yaml => dlink-config-dump.yaml} | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) rename http/misconfiguration/{d-link-auth-bypass.yaml => dlink-config-dump.yaml} (85%) diff --git a/http/misconfiguration/d-link-auth-bypass.yaml b/http/misconfiguration/dlink-config-dump.yaml similarity index 85% rename from http/misconfiguration/d-link-auth-bypass.yaml rename to http/misconfiguration/dlink-config-dump.yaml index 9e81457ecf..ce333b408a 100644 --- a/http/misconfiguration/d-link-auth-bypass.yaml +++ b/http/misconfiguration/dlink-config-dump.yaml @@ -1,7 +1,7 @@ -id: d-link-auth-bypass +id: dlink-config-dump info: - name: D-Link DAP-1325 - Broken Access Control + name: D-Link DAP-1325 - Information Disclosure author: gy741 severity: critical description: | @@ -12,7 +12,7 @@ info: metadata: max-request: 1 shodan-query: title:"D-LINK" - tags: config,dump,dlink,auth-bypass + tags: config,dump,dlink,auth-bypass,disclosure http: - method: GET @@ -25,6 +25,7 @@ http: part: body words: - "Password" + case-insensitive: true - type: regex part: header