Merge pull request #1138 from projectdiscovery/backup-file

Added settings-php-files and more tags
patch-1
PD-Team 2021-03-24 15:24:06 +05:30 committed by GitHub
commit ca12c1fef7
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
7 changed files with 37 additions and 2 deletions

View File

@ -4,6 +4,7 @@ info:
name: OpenAPI name: OpenAPI
author: pdteam author: pdteam
severity: info severity: info
tags: api
requests: requests:
- method: GET - method: GET

View File

@ -1,9 +1,10 @@
id: swagger-api id: swagger-api
info: info:
name: Swagger API name: Public Swagger API
author: pd-team author: pdteam
severity: info severity: info
tags: api,swagger
requests: requests:
- method: GET - method: GET

View File

@ -4,6 +4,7 @@ info:
name: wadl file disclosure name: wadl file disclosure
author: 0xrudra & manuelbua author: 0xrudra & manuelbua
severity: info severity: info
tags: api
# References: # References:
# - https://github.com/dwisiswant0/wadl-dumper # - https://github.com/dwisiswant0/wadl-dumper

View File

@ -4,6 +4,7 @@ info:
name: wsdl-detect name: wsdl-detect
author: jarijaas author: jarijaas
severity: info severity: info
tags: api
# This detects web services that have WSDL (https://www.w3.org/TR/wsdl/) # This detects web services that have WSDL (https://www.w3.org/TR/wsdl/)
# For instance, SOAP services, such as: https://docs.microsoft.com/en-us/xamarin/xamarin-forms/data-cloud/web-services/asmx # For instance, SOAP services, such as: https://docs.microsoft.com/en-us/xamarin/xamarin-forms/data-cloud/web-services/asmx

View File

@ -0,0 +1,29 @@
id: settings-php-files
info:
name: settings.php information disclosure
author: sheikhrishad
severity: medium
tags: backup
requests:
- method: GET
path:
- "{{BaseURL}}/settings.php.bak"
- "{{BaseURL}}/settings.php.dist"
- "{{BaseURL}}/settings.php.old"
- "{{BaseURL}}/settings.php.save"
- "{{BaseURL}}/settings.php.swp"
- "{{BaseURL}}/settings.php.txt"
matchers-condition: and
matchers:
- type: word
words:
- "DB_NAME"
- "DB"
condition: and
- type: status
status:
- 200

View File

@ -4,6 +4,7 @@ info:
name: MySQL Dump Files name: MySQL Dump Files
author: geeknik & @dwisiswant0 author: geeknik & @dwisiswant0
severity: medium severity: medium
tags: backup
requests: requests:
- method: GET - method: GET

View File

@ -4,6 +4,7 @@ info:
name: Compressed Web File name: Compressed Web File
author: Toufik Airane & @dwisiswant0 author: Toufik Airane & @dwisiswant0
severity: medium severity: medium
tags: backup
requests: requests:
- method: GET - method: GET