From fdae79ca4618994b57b53ad9cb04a733799d26d0 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Mon, 19 Sep 2022 20:03:44 +0530 Subject: [PATCH 1/5] Create bitbucket-public-repo.yaml --- misconfiguration/bitbucket-public-repo.yaml | 31 +++++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 misconfiguration/bitbucket-public-repo.yaml diff --git a/misconfiguration/bitbucket-public-repo.yaml b/misconfiguration/bitbucket-public-repo.yaml new file mode 100644 index 0000000000..3749371ee5 --- /dev/null +++ b/misconfiguration/bitbucket-public-repo.yaml @@ -0,0 +1,31 @@ +id: bitbucket-public-repo + +info: + name: BitBucket Public Visibility Repository + author: DhiyaneshDk + severity: low + tags: misconfig,bitbucket + +requests: + - method: GET + path: + - "{{BaseURL}}/repos?visibility=public" + - "{{BaseURL}}/bitbucket/repos?visibility=public" + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + part: body + words: + - 'Public Repositories - Bitbucket' + condition: and + + - type: word + part: header + words: + - "text/html" + + - type: status + status: + - 200 From cb54ff669a558f5a4480730d3ba393861e98cf10 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Mon, 19 Sep 2022 20:06:55 +0530 Subject: [PATCH 2/5] Update and rename bitbucket-public-repo.yaml to bitbucket-public-projects.yaml --- ...bucket-public-repo.yaml => bitbucket-public-projects.yaml} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename misconfiguration/{bitbucket-public-repo.yaml => bitbucket-public-projects.yaml} (86%) diff --git a/misconfiguration/bitbucket-public-repo.yaml b/misconfiguration/bitbucket-public-projects.yaml similarity index 86% rename from misconfiguration/bitbucket-public-repo.yaml rename to misconfiguration/bitbucket-public-projects.yaml index 3749371ee5..2b33328f1a 100644 --- a/misconfiguration/bitbucket-public-repo.yaml +++ b/misconfiguration/bitbucket-public-projects.yaml @@ -1,7 +1,7 @@ -id: bitbucket-public-repo +id: bitbucket-public-projects info: - name: BitBucket Public Visibility Repository + name: Atlassian Bitbucket Public Projects Exposure author: DhiyaneshDk severity: low tags: misconfig,bitbucket From 78a35d3d1edd262f03a952cc286ccef3f7ec3e60 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Mon, 19 Sep 2022 20:08:22 +0530 Subject: [PATCH 3/5] Update and rename bitbucket-public-projects.yaml to bitbucket-public-repository.yaml --- ...-public-projects.yaml => bitbucket-public-repository.yaml} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename misconfiguration/{bitbucket-public-projects.yaml => bitbucket-public-repository.yaml} (86%) diff --git a/misconfiguration/bitbucket-public-projects.yaml b/misconfiguration/bitbucket-public-repository.yaml similarity index 86% rename from misconfiguration/bitbucket-public-projects.yaml rename to misconfiguration/bitbucket-public-repository.yaml index 2b33328f1a..0f0463d364 100644 --- a/misconfiguration/bitbucket-public-projects.yaml +++ b/misconfiguration/bitbucket-public-repository.yaml @@ -1,7 +1,7 @@ -id: bitbucket-public-projects +id: bitbucket-public-repository info: - name: Atlassian Bitbucket Public Projects Exposure + name: Atlassian Bitbucket Public Repository Exposure author: DhiyaneshDk severity: low tags: misconfig,bitbucket From 1a0b8b27363018c1be8062f6665a62d58a88ed3d Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Mon, 19 Sep 2022 20:21:47 +0530 Subject: [PATCH 4/5] Update bitbucket-public-repository.yaml --- misconfiguration/bitbucket-public-repository.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/misconfiguration/bitbucket-public-repository.yaml b/misconfiguration/bitbucket-public-repository.yaml index 0f0463d364..909040e099 100644 --- a/misconfiguration/bitbucket-public-repository.yaml +++ b/misconfiguration/bitbucket-public-repository.yaml @@ -4,6 +4,9 @@ info: name: Atlassian Bitbucket Public Repository Exposure author: DhiyaneshDk severity: low + metadata: + verified: true + shodan-query: http.component:"Bitbucket" tags: misconfig,bitbucket requests: From 27e8de6c965427374a7ba927afa68c2029dee163 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Wed, 21 Sep 2022 00:09:58 +0530 Subject: [PATCH 5/5] Update bitbucket-public-repository.yaml --- misconfiguration/bitbucket-public-repository.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/misconfiguration/bitbucket-public-repository.yaml b/misconfiguration/bitbucket-public-repository.yaml index 909040e099..7349180660 100644 --- a/misconfiguration/bitbucket-public-repository.yaml +++ b/misconfiguration/bitbucket-public-repository.yaml @@ -22,7 +22,6 @@ requests: part: body words: - 'Public Repositories - Bitbucket' - condition: and - type: word part: header