From 3aa4a79e16f6231889d9cc48d6a14053bc6c3098 Mon Sep 17 00:00:00 2001 From: Arman <65326024+tess-ss@users.noreply.github.com> Date: Thu, 10 Nov 2022 09:12:12 -0800 Subject: [PATCH 1/3] Create ace-admin-dashboard.yaml --- misconfiguration/ace-admin-dashboard.yaml | 33 +++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 misconfiguration/ace-admin-dashboard.yaml diff --git a/misconfiguration/ace-admin-dashboard.yaml b/misconfiguration/ace-admin-dashboard.yaml new file mode 100644 index 0000000000..716880e854 --- /dev/null +++ b/misconfiguration/ace-admin-dashboard.yaml @@ -0,0 +1,33 @@ +id: ace-admin-dashboard + +info: + name: Ace Admin Dashboard Exposed + author: tess + severity: medium + metadata: + verified: true + shodan-query: title:"Dashboard - Ace Admin" + tags: misconfig,exposed,ace + +requests: + - method: GET + path: + - '{{BaseURL}}' + + matchers-condition: and + matchers: + - type: word + part: body + words: + - "Dashboard - Ace Admin" + - "overview & stats" + condition: and + + - type: word + part: header + words: + - "text/html" + + - type: status + status: + - 200 From c904a9ff0d8eaf925b5f55c8ab21aaa326b9c65d Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Thu, 10 Nov 2022 22:45:07 +0530 Subject: [PATCH 2/3] Update ace-admin-dashboard.yaml --- misconfiguration/ace-admin-dashboard.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/misconfiguration/ace-admin-dashboard.yaml b/misconfiguration/ace-admin-dashboard.yaml index 716880e854..ad86201720 100644 --- a/misconfiguration/ace-admin-dashboard.yaml +++ b/misconfiguration/ace-admin-dashboard.yaml @@ -1,13 +1,13 @@ id: ace-admin-dashboard info: - name: Ace Admin Dashboard Exposed + name: Ace Admin Dashboard Exposure author: tess severity: medium metadata: verified: true shodan-query: title:"Dashboard - Ace Admin" - tags: misconfig,exposed,ace + tags: misconfig,exposure,ace requests: - method: GET From 7a286ecec38c7c1e26ff321bf1e9673bb09ea440 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Thu, 10 Nov 2022 22:45:24 +0530 Subject: [PATCH 3/3] Update ace-admin-dashboard.yaml --- misconfiguration/ace-admin-dashboard.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/misconfiguration/ace-admin-dashboard.yaml b/misconfiguration/ace-admin-dashboard.yaml index ad86201720..1e63d1d541 100644 --- a/misconfiguration/ace-admin-dashboard.yaml +++ b/misconfiguration/ace-admin-dashboard.yaml @@ -7,7 +7,7 @@ info: metadata: verified: true shodan-query: title:"Dashboard - Ace Admin" - tags: misconfig,exposure,ace + tags: misconfig,exposure,aceadmin requests: - method: GET