diff --git a/http/default-logins/nginx/nginx-proxy-manager-default-login.yaml b/http/default-logins/nginx/nginx-proxy-manager-default-login.yaml new file mode 100644 index 0000000000..5ebbed22dd --- /dev/null +++ b/http/default-logins/nginx/nginx-proxy-manager-default-login.yaml @@ -0,0 +1,30 @@ +id: nginx-proxy-manager-default-login + +info: + name: Nginx Proxy Manager - Default Login + author: barttran2000 + severity: high + description: | + Default Nginx Proxy Manager credentials was discovered. + metadata: + shodan-query: html:"Nginx Proxy Manager" + verified: true + max-request: 1 + tags: nginx,proxy-manager,default-login + +http: + - raw: + - | + POST /api/tokens HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/json + + {"identity": "admin@example.com","secret": "changeme"} + + matchers: + - type: dsl + dsl: + - contains_all(body, "{\"token", "expires\":") + - contains(content_type, "application/json") + - status_code == 200 + condition: and