Create office365-open-redirect.yaml
parent
22aa5c67ee
commit
dbab8fb57a
|
@ -0,0 +1,20 @@
|
|||
id: office365-open-redirect
|
||||
|
||||
info:
|
||||
name: Office365 Open Redirect From Autodiscover
|
||||
author: dhiyaneshDk
|
||||
severity: low
|
||||
reference: https://medium.com/@heinjame/office365-open-redirect-from-autodiscover-64284d26c168
|
||||
tags: redirect
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
path:
|
||||
- "{{BaseURL}}/autodiscover/autodiscover.json/v1.0/anyname@attacker.com?Protocol=Autodiscoverv1"
|
||||
|
||||
redirects: true
|
||||
max-redirects: 2
|
||||
matchers:
|
||||
- type: word
|
||||
words:
|
||||
- "Attacker"
|
Loading…
Reference in New Issue