diff --git a/http/exposed-panels/ibm/ibm-advanced-system-management.yaml b/http/exposed-panels/ibm/ibm-advanced-system-management.yaml index e242b127b0..0a61fbcbbe 100644 --- a/http/exposed-panels/ibm/ibm-advanced-system-management.yaml +++ b/http/exposed-panels/ibm/ibm-advanced-system-management.yaml @@ -2,29 +2,37 @@ id: ibm-advanced-system-management info: name: IBM Advanced System Management Panel - Detect - author: dhiyaneshDK + author: dhiyaneshDK,righettod severity: info description: IBM Advanced System Management panel was detected. + reference: + - https://www.ibm.com/docs/en/power8/9080-MME?topic=operations-advanced-system-management classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cwe-id: CWE-200 metadata: max-request: 1 shodan-query: http.title:"Advanced System Management" - tags: panel,ibm + tags: panel,ibm,login,detect http: - method: GET path: - - '{{BaseURL}}/cgi-bin/cgi' + - '{{BaseURL}}/cgi-bin/cgi?form=1' matchers-condition: and matchers: - type: word words: - - 'Advanced System Management' + - 'Advanced System Management' - type: status status: - 200 -# digest: 4b0a004830460221009daf361941cf6a67b73fee3bb9226b6b67110d9c1335ebf49d0770b8684ce10f022100d3802939beeb74aa396c225600170a5e99f2dc8080a17ef6291414852f62b6a1:922c64590222798bb761d5b6d8e72950 \ No newline at end of file + + extractors: + - type: regex + part: body + group: 1 + regex: + - '(?i)Update\s+Access\s+Key\s+Exp\s+Date\s+\(YYYY-MM-DD\):\s+([0-9\-]+)'