From 0f8e22ce423fecd2810a116ae4bab1f571c41ff4 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Wed, 3 Jan 2024 16:40:08 +0530 Subject: [PATCH 1/3] Update gitlab-public-signup.yaml --- http/misconfiguration/gitlab/gitlab-public-signup.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/http/misconfiguration/gitlab/gitlab-public-signup.yaml b/http/misconfiguration/gitlab/gitlab-public-signup.yaml index c7fb302f8a..15b7206195 100644 --- a/http/misconfiguration/gitlab/gitlab-public-signup.yaml +++ b/http/misconfiguration/gitlab/gitlab-public-signup.yaml @@ -13,7 +13,9 @@ http: - method: GET path: - "{{BaseURL}}/users/sign_in" + - "{{BaseURL}}/users/sign_up" + stop-at-first-match: true matchers-condition: and matchers: - type: word From 77f48c546394e6b86e07d492aa1a3be337718abc Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Wed, 3 Jan 2024 16:41:22 +0530 Subject: [PATCH 2/3] Delete http/misconfiguration/gitlab/gitlab-public-registration.yaml --- .../gitlab/gitlab-public-registration.yaml | 38 ------------------- 1 file changed, 38 deletions(-) delete mode 100644 http/misconfiguration/gitlab/gitlab-public-registration.yaml diff --git a/http/misconfiguration/gitlab/gitlab-public-registration.yaml b/http/misconfiguration/gitlab/gitlab-public-registration.yaml deleted file mode 100644 index 45738dec8d..0000000000 --- a/http/misconfiguration/gitlab/gitlab-public-registration.yaml +++ /dev/null @@ -1,38 +0,0 @@ -id: gitlab-public-registration - -info: - name: GitLab public registration of new user - Detect - author: axrk - severity: info - metadata: - max-request: 1 - shodan-query: http.title:"GitLab" - tags: gitlab,misconfig - -http: - - method: GET - path: - - "{{BaseURL}}/users/sign_up" - - matchers-condition: and - matchers: - - type: word - words: - - 'Register' - - 'data-qa-selector="new_user_register_button"' - condition: or - - - type: word - words: - - 'https://about.gitlab.com' - - - type: status - status: - - 200 - - - type: word - negative: true - words: - - '' - -# digest: 490a0046304402204827554d0c5e27a1b7b6a44996c4c0d926d1aa115589544880385745b77c6e5b02201da92f300b8fd99cedf9704418984afcb842b71c0e22e7f9f03f755699b7b8aa:922c64590222798bb761d5b6d8e72950 From 3bcbe6b6b42b6dafc6093e0aab680ad0c7b7354b Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Wed, 3 Jan 2024 16:41:50 +0530 Subject: [PATCH 3/3] updated author name --- http/misconfiguration/gitlab/gitlab-public-signup.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/http/misconfiguration/gitlab/gitlab-public-signup.yaml b/http/misconfiguration/gitlab/gitlab-public-signup.yaml index 15b7206195..fe1d34758e 100644 --- a/http/misconfiguration/gitlab/gitlab-public-signup.yaml +++ b/http/misconfiguration/gitlab/gitlab-public-signup.yaml @@ -2,7 +2,7 @@ id: gitlab-public-signup info: name: GitLab public signup - author: pdteam + author: pdteam,axrk severity: info metadata: max-request: 1