From e66eb0fdc367586bc16ac15cbf73a42eeb3a694e Mon Sep 17 00:00:00 2001 From: sandeep <8293321+bauthard@users.noreply.github.com> Date: Wed, 24 Feb 2021 22:55:41 +0530 Subject: [PATCH] misc changes --- misconfiguration/hadoop-unauth.yaml | 2 +- misconfiguration/haproxy-status.yaml | 5 ++--- misconfiguration/java-melody-exposed.yaml | 7 +++++-- misconfiguration/tcpconfig.yaml | 2 +- misconfiguration/ups-status.yaml | 2 +- 5 files changed, 10 insertions(+), 8 deletions(-) diff --git a/misconfiguration/hadoop-unauth.yaml b/misconfiguration/hadoop-unauth.yaml index a034f23851..564fcd5003 100644 --- a/misconfiguration/hadoop-unauth.yaml +++ b/misconfiguration/hadoop-unauth.yaml @@ -2,7 +2,7 @@ id: hadoop-unauth info: name: Apache Hadoop Unauth - author: pd-team + author: pdteam severity: low requests: diff --git a/misconfiguration/haproxy-status.yaml b/misconfiguration/haproxy-status.yaml index 1928777ab7..fbeb08d159 100644 --- a/misconfiguration/haproxy-status.yaml +++ b/misconfiguration/haproxy-status.yaml @@ -3,14 +3,13 @@ id: haproxy-status info: name: HA Proxy Statistics author: dhiyaneshDK - severity: Medium + severity: medium reference: https://www.exploit-db.com/ghdb/4191 - tags: logs,status + tags: logs requests: - method: GET path: - - "{{BaseURL}}" - "{{BaseURL}}/haproxy-status" matchers-condition: and diff --git a/misconfiguration/java-melody-exposed.yaml b/misconfiguration/java-melody-exposed.yaml index 7b4b953f01..915a3a7e1a 100644 --- a/misconfiguration/java-melody-exposed.yaml +++ b/misconfiguration/java-melody-exposed.yaml @@ -3,16 +3,19 @@ id: java-melody-exposed info: name: JavaMelody Monitoring Exposed author: dhiyaneshDK - severity: Medium + severity: medium requests: - method: GET path: - - '{{BaseURL}}' - '{{BaseURL}}/monitoring' - '{{BaseURL}}/..%3B/monitoring' + matchers-condition: and matchers: - type: word words: - 'Monitoring JavaMelody on' + - type: status + status: + - 200 \ No newline at end of file diff --git a/misconfiguration/tcpconfig.yaml b/misconfiguration/tcpconfig.yaml index c8f5e9b38d..283f9b86d7 100644 --- a/misconfiguration/tcpconfig.yaml +++ b/misconfiguration/tcpconfig.yaml @@ -5,7 +5,7 @@ info: author: dhiyaneshDK severity: low reference: https://www.exploit-db.com/ghdb/6782 - tags: logs,status + tags: logs requests: - method: GET diff --git a/misconfiguration/ups-status.yaml b/misconfiguration/ups-status.yaml index 481f53a7e8..b1906a58a0 100644 --- a/misconfiguration/ups-status.yaml +++ b/misconfiguration/ups-status.yaml @@ -5,7 +5,7 @@ info: author: dhiyaneshDK severity: low reference: https://www.exploit-db.com/ghdb/752 - tags: logs,status + tags: logs requests: - method: GET