Revert "remove exposure tag from misconfiguration templates"

This reverts commit 3a815a58a1.
patch-1
ErikOwen 2023-06-30 15:40:59 -07:00
parent 7fe3be43ea
commit e095c6063e
191 changed files with 193 additions and 189 deletions

View File

@ -13,7 +13,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Dashboard - Ace Admin"
tags: misconfig,aceadmin
tags: misconfig,exposure,aceadmin
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: misconfig,aem,adobe
tags: misconfig,aem,adobe,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: aem,adobe,misconfig
tags: exposure,aem,adobe,misconfig
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: misconfig,aem,adobe
tags: misconfig,aem,adobe,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: misconfig,aem,adobe
tags: misconfig,aem,adobe,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: misconfig,aem,adobe
tags: misconfig,aem,adobe,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: misconfig,aem,adobe
tags: misconfig,aem,adobe,exposure
http:
- method: GET

View File

@ -12,7 +12,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: misconfig,aem,adobe
tags: misconfig,aem,adobe,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
metadata:
max-request: 2
verified: true
tags: aem,adobe,misconfig
tags: aem,adobe,misconfig,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: misconfig,aem,adobe
tags: misconfig,aem,adobe,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
shodan-query:
- http.title:"AEM Sign In"
- http.component:"Adobe Experience Manager"
tags: misconfig,aem,adobe
tags: misconfig,aem,adobe,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.html:"Ampache Update"
tags: misconfig,ampache
tags: misconfig,ampache,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Apache Drill"
tags: misconfig,apache,drill
tags: misconfig,exposure,apache,drill
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
max-request: 2
verified: true
shodan-query: title:"Struts2 Showcase"
tags: apache,struts,showcase,misconfig
tags: apache,struts,showcase,misconfig,exposure
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
metadata:
max-request: 1
fofa-query: app="Kafka-Manager"
tags: misconfig,apache,kafka,unauth
tags: misconfig,apache,kafka,unauth,exposure
http:
- method: GET

View File

@ -5,7 +5,7 @@ info:
author: tess
severity: low
description: Searches for exposed awstats Internal Information.
tags: misconfig,aws,amazon,awstats,oss
tags: misconfig,aws,exposure,amazon,awstats,oss
metadata:
max-request: 1

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Blackbox Exporter"
tags: blackbox,debug,misconfig
tags: blackbox,exposure,debug,misconfig
http:
- method: GET

View File

@ -13,7 +13,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Dashboard - Bootstrap Admin Template"
tags: bootstrap,panel,misconfig
tags: bootstrap,panel,misconfig,exposure
http:
- method: GET

View File

@ -13,7 +13,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"cAdvisor"
tags: misconfig,dashboard
tags: exposure,misconfig,dashboard
http:
- method: GET

View File

@ -6,7 +6,7 @@ info:
severity: high
reference:
- https://github.com/detectify/ugly-duckling/blob/master/modules/crowdsourced/clockwork-dashboard-exposure.json
tags: unauth,misconfig
tags: exposure,unauth,misconfig
metadata:
max-request: 1

View File

@ -9,7 +9,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"instance_metadata"
tags: misconfig,devops,cloud,aws,gcp
tags: misconfig,exposure,devops,cloud,aws,gcp
http:
- method: GET

View File

@ -5,7 +5,7 @@ info:
author: c-sh0
severity: medium
description: Searches for exposed Cobbler Directories
tags: cobbler,misconfig
tags: cobbler,exposure,misconfig
metadata:
max-request: 2

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"CodeMeter"
tags: misconfig,codemeter
tags: misconfig,exposure,codemeter
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Codis • Dashboard"
tags: misconfig,codis
tags: misconfig,exposure,codis
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Collectd Exporter"
tags: collectd,debug,misconfig
tags: collectd,exposure,debug,misconfig
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Dashboard - Confluence"
tags: misconfig,confluence,atlassian
tags: misconfig,exposure,confluence,atlassian
http:
- method: GET

View File

@ -12,7 +12,7 @@ info:
max-request: 1
verified: true
shodan-query: http.html:"corebos"
tags: corebos,huntr,misconfig
tags: exposure,corebos,huntr,misconfig
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"Sorry, the requested URL"
tags: bottle,debug,misconfig
tags: bottle,exposure,debug,misconfig
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"Werkzeug powered traceback interpreter"
tags: werkzeug,debug,misconfig
tags: werkzeug,exposure,debug,misconfig
http:
- method: GET

View File

@ -12,7 +12,7 @@ info:
metadata:
max-request: 1
shodan-query: http.title:"Dgraph Ratel Dashboard"
tags: unauth,panel,misconfig
tags: exposure,unauth,panel,misconfig
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Docmosis Tornado"
tags: misconfig,tornado
tags: misconfig,tornado,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Elastic HD Dashboard"
tags: misconfig,elastic
tags: misconfig,exposure,elastic
http:
- method: GET

View File

@ -13,7 +13,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Encompass CM1 Home Page"
tags: misconfig,encompass
tags: misconfig,encompass,exposure
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Envoy Admin"
tags: misconfig,envoy
tags: misconfig,envoy,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.html:"ESP Easy Mega"
tags: misconfig,espeasy
tags: misconfig,espeasy,exposure
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Dashboard - ESPHome"
tags: misconfig,esphome,iot
tags: misconfig,esphome,exposure,iot
http:
- method: GET

View File

@ -12,7 +12,7 @@ info:
max-request: 1
verified: 'true'
shodan-query: http.favicon.hash:-977323269
tags: everything,listing,voidtools,misconfig
tags: exposure,everything,listing,voidtools,misconfig
http:
- method: GET

View File

@ -12,7 +12,7 @@ info:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cwe-id: CWE-434
tags: jquery,edb,misconfig
tags: exposure,jquery,edb,misconfig
metadata:
max-request: 1

View File

@ -4,7 +4,7 @@ info:
name: Publicly exposed Kafdrop Interface
author: dhiyaneshDk
severity: low
tags: misconfig,kafdrop
tags: exposure,misconfig,kafdrop
metadata:
max-request: 1

View File

@ -6,7 +6,7 @@ info:
severity: info
reference:
- https://docs.microsoft.com/en-us/archive/blogs/fabdulwahab/security-protecting-sharepoint-server-applications
tags: misconfig,frontpage
tags: misconfig,exposure,frontpage
metadata:
max-request: 2

View File

@ -10,7 +10,7 @@ info:
metadata:
max-request: 1
shodan-query: http.title:"GitLab"
tags: gitlab,misconfig
tags: gitlab,exposure,misconfig
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
metadata:
max-request: 2
shodan-query: http.title:"GitLab"
tags: gitlab,misconfig
tags: gitlab,exposure,misconfig
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Global Traffic Statistics"
tags: misconfig,global
tags: misconfig,global,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
metadata:
max-request: 1
shodan-query: http.title:"Create a pipeline - Go",html:"GoCD Version"
tags: go,gocd,config,misconfig
tags: go,gocd,config,exposure,misconfig
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
metadata:
max-request: 1
shodan-query: http.title:"Create a pipeline - Go",html:"GoCD Version"
tags: go,gocd,misconfig
tags: go,gocd,exposure,misconfig
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"haproxy exporter"
tags: haproxy,debug,misconfig
tags: haproxy,exposure,debug,misconfig
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Health Checks UI"
tags: misconfig
tags: misconfig,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"HFS /"
tags: misconfig,hfs
tags: misconfig,hfs,exposure
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
metadata:
max-request: 5
shodan-query: http.html:"IBM WebSphere Portal"
tags: ibm,websphere,misconfig
tags: ibm,exposure,websphere,misconfig
http:
- method: GET

View File

@ -11,7 +11,8 @@ info:
metadata:
max-request: 1
verified: true
tags: ibm,websphere,misconfig
tags: ibm,websphere,exposure,misconfig
verified: "true"
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.favicon.hash:-347188002
tags: misconfig,install,acunetix
tags: misconfig,exposure,install,acunetix
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"For the Love of Music - Installation"
tags: misconfig,ampache,install
tags: misconfig,ampache,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.title:"Bagisto Installer"
tags: misconfig,bagisto,install
tags: misconfig,bagisto,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 2
verified: true
shodan-query: title:"Install Binom"
tags: misconfig,binom,install
tags: misconfig,binom,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"Blesta installer"
tags: misconfig,blesta,install
tags: misconfig,blesta,install,exposure
http:
- method: GET

View File

@ -15,7 +15,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"- setup" html:"Modem setup"
tags: scada,circontrol,circarlife,setup,panel,installer,misconfig
tags: scada,circontrol,circarlife,setup,exposure,panel,installer,misconfig
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"CloudCenter Installer"
tags: misconfig,cisco,cloudcenter,install
tags: misconfig,cisco,cloudcenter,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.title:"Codeigniter Application Installer"
tags: misconfig,codeigniter,install
tags: misconfig,codeigniter,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Install concrete"
tags: misconfig,install,concrete
tags: misconfig,exposure,install,concrete
http:
- method: GET

View File

@ -7,7 +7,7 @@ info:
metadata:
max-request: 1
verified: true
tags: misconfig,contentify,install
tags: misconfig,contentify,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"DokuWiki"
tags: misconfig,dokuwiki,install
tags: misconfig,dokuwiki,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Dolibarr install or upgrade"
tags: misconfig,install
tags: misconfig,exposure,install
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"eShop Installer"
tags: misconfig,eshop,install
tags: misconfig,eshop,install,exposure
http:
- method: GET

View File

@ -7,7 +7,7 @@ info:
metadata:
max-request: 1
verified: true
tags: misconfig,espeasy,install
tags: misconfig,espeasy,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"FacturaScripts installer"
tags: misconfig,facturascripts,install
tags: misconfig,facturascripts,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"GeniusOcean Installer"
tags: misconfig,geniusocean,install
tags: misconfig,geniusocean,install,exposure
http:
- method: GET

View File

@ -11,7 +11,7 @@ info:
cwe-id: CWE-284
reference:
- http://get-simple.info/
tags: getsimple,installer,misconfig
tags: getsimple,exposure,installer,misconfig
metadata:
max-request: 1

View File

@ -13,7 +13,7 @@ info:
max-request: 1
verified: true
shodan-query: http.title:"Installation - Gogs"
tags: misconfig,gogs,install
tags: misconfig,exposure,gogs,install
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.title:"ImpressPages installation wizard"
tags: misconfig,install,impresspages
tags: misconfig,exposure,install,impresspages
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"LMSZAI - Learning Management System"
tags: misconfig,blesta,install
tags: misconfig,blesta,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"Lychee-installer"
tags: misconfig,lychee,install
tags: misconfig,lychee,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"Magento Installation"
tags: misconfig,magento,install
tags: misconfig,magento,install,exposure
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Magnolia Installation"
tags: magnolia,installer,misconfig
tags: magnolia,exposure,installer,misconfig
http:
- method: GET

View File

@ -15,7 +15,7 @@ info:
max-request: 1
verified: true
shodan-query: http.title:"mcloud-installer-web"
tags: panel,mcloud,misconfig
tags: panel,mcloud,exposure,misconfig
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Installation Moodle"
tags: misconfig,moodle,install
tags: misconfig,moodle,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Nagios XI"
tags: misconfig,install,nagiosxi
tags: misconfig,exposure,install,nagiosxi
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.favicon.hash:-1575154882
tags: misconfig,install,netsparker
tags: misconfig,exposure,install,netsparker
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"NginX Auto Installer"
tags: misconfig,nginx,install
tags: misconfig,nginx,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"NodeBB Web Installer"
tags: misconfig,nodebb,install
tags: misconfig,nodebb,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"OpenMage Installation Wizard"
tags: misconfig,openmage,install
tags: misconfig,openmage,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"openSIS"
tags: misconfig,opensis,install
tags: misconfig,opensis,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.title:"OrangeHRM Web Installation Wizard"
tags: misconfig,install,orangehrm
tags: misconfig,exposure,install,orangehrm
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 2
verified: true
shodan-query: title:"owncloud"
tags: misconfig,owncloud,install
tags: misconfig,owncloud,exposure,install
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"OXID eShop installation"
tags: misconfig,oxid,eshop,install
tags: misconfig,oxid,eshop,install,exposure
http:
- method: GET

View File

@ -10,7 +10,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Pagekit Installer"
tags: misconfig,pagekit,install
tags: misconfig,pagekit,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:" Permissions | Installer"
tags: misconfig,permissions,install
tags: misconfig,permissions,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"Installation Panel"
tags: misconfig,phpbb,install
tags: misconfig,phpbb,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Powered by phpwind"
tags: misconfig,phpwind,install
tags: misconfig,phpwind,exposure,install
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: http.title:"PMM Installation Wizard"
tags: misconfig,install,pmm
tags: misconfig,exposure,install,pmm
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"PrestaShop Installation Assistant"
tags: misconfig,prestashop,install
tags: misconfig,prestashop,exposure,install
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 2
verified: true
shodan-query: title:"ProcessWire 3.x Installer"
tags: misconfig,processwire,install
tags: misconfig,processwire,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"SERVER MONITOR - Install"
tags: misconfig,monitor,install
tags: misconfig,monitor,exposure,install
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"SMF Installer"
tags: misconfig,smf,install
tags: misconfig,smf,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"SumoWebTools Installer"
tags: misconfig,sumowebtools,install
tags: misconfig,sumowebtools,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Tasmota"
tags: misconfig,tasmota,install
tags: misconfig,tasmota,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"TestRail Installation Wizard"
tags: misconfig,testrail,install
tags: misconfig,testrail,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"Turbo Website Reviewer"
tags: turbo,misconfig,install
tags: turbo,misconfig,exposure,install
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"UniFi Wizard"
tags: misconfig,install,unifi
tags: misconfig,install,unifi,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: title:"UVDesk Helpdesk Community Edition - Installation Wizard"
tags: misconfig,uvdesk,install
tags: misconfig,uvdesk,install,exposure
http:
- method: GET

View File

@ -8,7 +8,7 @@ info:
max-request: 1
verified: true
shodan-query: html:"Welcome to Vtiger CRM"
tags: misconfig,vtiger,install
tags: misconfig,vtiger,install,exposure
http:
- method: GET

Some files were not shown because too many files have changed in this diff Show More