diff --git a/http/misconfiguration/installer/combodo-itop-installer.yaml b/http/misconfiguration/installer/combodo-itop-installer.yaml new file mode 100644 index 0000000000..a21351aba1 --- /dev/null +++ b/http/misconfiguration/installer/combodo-itop-installer.yaml @@ -0,0 +1,33 @@ +id: combodo-itop-installer + +info: + name: Combodo iTop Installer/Upgrade - Exposure + author: DhiyaneshDK + severity: high + reference: + - https://www.itophub.io/wiki/page?id=2_4_0:install:install_wizard + metadata: + max-request: 1 + verified: true + shodan-query: html:"Installation" html:"itop" + tags: misconfig,itop,install,exposure + +http: + - method: GET + path: + - '{{BaseURL}}/setup/wizard.php' + - '{{BaseURL}}/itop/setup/wizard.php' + + stop-at-first-match: true + matchers-condition: and + matchers: + - type: word + part: body + words: + - "iTop Installation Wizard" + - "/setup.js" + condition: and + + - type: status + status: + - 200