Commit Graph

526 Commits (patch-14)

Author SHA1 Message Date
Prince Chaddha f9fd870fbb misc changes 2023-06-12 18:54:55 +05:30
Krzysztof Zając be44554c36 More paths 2023-06-08 17:16:32 +02:00
Krzysztof Zając 4ec10ca65f More effective Roundcube log disclosure template. 2023-06-08 17:12:16 +02:00
ErikOwen 9921dfc33c fix bugs 2023-06-05 11:08:25 -07:00
ErikOwen 6bd8403df2 remove tech tag from exposures templates 2023-06-05 11:08:24 -07:00
ErikOwen df937f18b8 remove misconfig tag from exposures 2023-06-05 11:07:07 -07:00
ErikOwen a85b495576 add exposure tag to templates in http/exposures 2023-06-05 11:03:55 -07:00
sandeep e53d19f583 boolean format update 2023-06-04 13:43:42 +05:30
GitHub Action df5a969b80 Auto Generated CVE annotations [Sat Jun 3 18:56:35 UTC 2023] 🤖 2023-06-03 18:56:35 +00:00
Ritik Chaddha 5606478cc2 update max-req=> max-request 2023-06-01 23:08:50 +05:30
Ritik Chaddha d6bc852482 Revert "update metadata"
This reverts commit 7393a6e107.
2023-06-01 22:48:28 +05:30
Ritik Chaddha 7393a6e107 update metadata 2023-06-01 22:45:35 +05:30
Ritik Chaddha 56d01f88d7
Merge pull request #7256 from projectdiscovery/file-http-token
File and Token Based Templates
2023-05-30 10:46:14 +05:30
Dhiyaneshwaran 8b64c89438
fix lint 2023-05-23 15:36:55 +05:30
Dhiyaneshwaran 2abbdbd2b5
http protocol update 2023-05-23 15:33:26 +05:30
Dhiyaneshwaran d7a54b0b00
added reference 2023-05-23 15:32:28 +05:30
Dhiyaneshwaran 3f2623aaea
Create blazor-boot.yaml 2023-05-23 15:30:08 +05:30
m4lwhere cddcf8c8c1 linting fixes 2023-05-21 16:19:27 -04:00
m4lwhere 5263ac918c Added templates to identify /.aws/credenitals and /.aws/config 2023-05-21 10:25:38 -04:00
Dhiyaneshwaran 2f2ca66aa9 fix duplicate template id 2023-05-19 02:06:30 +05:30
Dhiyaneshwaran d862b446ee fix regex compilation issue 2023-05-19 02:02:00 +05:30
Dhiyaneshwaran 1dad4cfd50 Token and File Based Templates 2023-05-19 01:53:21 +05:30
Ritik Chaddha f1b941e2fb
Create jeecg-boot-swagger.yaml 2023-05-18 01:02:35 +05:30
Dhiyaneshwaran d280f157c2
added negative matcher 2023-05-17 01:37:28 +05:30
Dhiyaneshwaran aeb0c0592a
minor update 2023-05-15 01:02:48 +05:30
Dhiyaneshwaran 7d793835cf
add new endpoint and reference 2023-05-15 01:02:22 +05:30
J4vaovo 7d99c36773
Update config-properties-exposure 2023-05-14 19:31:28 +08:00
J4vaovo b00f399e40
Create config-properties-exposure 2023-05-14 19:27:37 +08:00
sandeep 67c4fae6bb misc update 2023-05-11 18:10:12 +05:30
Ritik Chaddha 281f036d10
Merge pull request #7190 from projectdiscovery/platformio-ini
Create platformio-ini.yaml
2023-05-11 15:35:26 +05:30
Ritik Chaddha 8bb49ad232
added google-query 2023-05-11 15:32:42 +05:30
Dhiyaneshwaran c6a09150a3
fix false positive 2023-05-11 01:41:34 +05:30
Dhiyaneshwaran 2cd9630abd
change to http attribute 2023-05-08 15:01:22 +05:30
Dhiyaneshwaran 064ccf7b80
Create nginx-shards.yaml 2023-05-08 15:00:15 +05:30
Dhiyaneshwaran 6a8446b887
Create platformio-ini.yaml 2023-05-08 13:38:14 +05:30
Ritik Chaddha cc4a213613
Merge pull request #7158 from DhiyaneshGeek/sb-meetup
Sb meetup
2023-05-06 00:00:58 +05:30
Dhiyaneshwaran 2c6d6cb3c0 Update postman-key.yaml 2023-04-30 17:49:29 +05:30
Dhiyaneshwaran 9286f2174d
Create postman-key.yaml 2023-04-30 13:53:37 +05:30
sandeep 1f5b1f2c47 Added max request counter of each template 2023-04-28 13:41:21 +05:30
Prince Chaddha e0af666e1c
Refactoring the directory structure based on protocols (#7137)
* moving http templates

* updated cves.json

* moved network CVEs

* updated scripts

* updated workflows

* updated requests to http

* replaced network to tcp

---------

Co-authored-by: sandeep <8293321+ehsandeep@users.noreply.github.com>
2023-04-27 09:58:59 +05:30
ghost 27b686c4cd chore: sign templates 🤖 2024-09-12 05:14:02 +00:00
Parth Malhotra 7d276ebee0 Fix classification
Fix classification
2024-09-10 14:38:16 +05:30
Parth Malhotra b2e470c37e Fix classification position
Fix classification position
2024-09-10 14:11:12 +05:30
Parth Malhotra 33f6932472 Add missing cpes
Added missing cpes
2024-09-10 13:52:50 +05:30
ghost 348761601b chore: sign templates 🤖 2024-09-10 06:21:56 +00:00
ghost 35442a1d88 chore: sign templates 🤖 2024-09-10 06:18:38 +00:00
Dhiyaneshwaran 73fdd966db
Merge pull request #10639 from icarot/main
Create apache-jspwiki-detect.yaml and apache-jspwiki-IP-userenum.yaml
2024-09-10 11:46:38 +05:30
Ritik Chaddha 6ce348bcad
updated matcher & removed extractor 2024-09-09 21:25:57 +04:00
ghost 15358973c7 chore: sign templates 🤖 2024-09-04 15:35:46 +00:00
ghost 6f88f18e43 chore: sign templates 🤖 2024-09-02 18:00:49 +00:00
Ritik Chaddha 241e991f36
Merge pull request #10643 from 0xPugal/main
Add CVE-2023-47684
2024-09-02 21:58:36 +04:00
ghost f3ee4d254c chore: sign templates 🤖 2024-09-02 17:52:47 +00:00
Dhiyaneshwaran 83876ce34e
fix fp 2024-09-02 15:11:52 +05:30
Dhiyaneshwaran 39fcb221d8
Fix FP exposed-gitignore & mercurial-hgignore 2024-09-02 15:10:57 +05:30
Dhiyaneshwaran 3fcd14c19c
Update and rename apache-jspwiki-IP-userenum.yaml to apache-jspwiki-ip-userenum.yaml 2024-09-02 08:24:19 +05:30
Pugalarasan 049b9bd704
Update php-backup-files.yaml 2024-09-01 22:59:38 +05:30
Pugalarasan c94f025b45
Update collibra-properties.yaml 2024-09-01 22:55:26 +05:30
Icaro Torres 573a378d2f
Create apache-jspwiki-IP-userenum.yaml
Enumerates the IP Address and users that is currently accessing an Apache JSPWiki web application, leading open source WikiWiki engine, feature-rich and built around standard JEE components (Java, servlets, JSP).
2024-08-31 08:34:27 -03:00
GitHub Action 60081c7778 Auto Template Signing [Tue Aug 6 07:28:53 UTC 2024] 🤖 2024-08-06 07:28:54 +00:00
Dhiyaneshwaran 9efe1f1530
add additional path 2024-08-01 11:11:38 +05:30
Dhiyaneshwaran 1e9e72036a
additional matcher 2024-08-01 11:07:13 +05:30
Dhiyaneshwaran 6160566185
fix -error 2024-08-01 10:59:59 +05:30
Dhiyaneshwaran 95dd646e7a
Create gitlab-ci-yml.yaml 2024-08-01 03:43:12 +05:30
GitHub Action b687877f3d Auto Template Signing [Fri Jul 26 13:07:14 UTC 2024] 🤖 2024-07-26 13:07:14 +00:00
Dhiyaneshwaran 30c39fe9cf
Merge pull request #10363 from projectdiscovery/repace-domains
updated example and evil.com domains
2024-07-26 18:32:10 +05:30
Dhiyaneshwaran aee1229604
trail-space-fix 2024-07-23 19:18:26 +05:30
Prince Chaddha 09962be03e updated example and evil.com domains 2024-07-23 16:51:51 +04:00
GitHub Action 987152cb79 Auto Template Signing [Tue Jul 23 12:15:01 UTC 2024] 🤖 2024-07-23 12:15:02 +00:00
Prince Chaddha 22f763e16f
Update exposed-svn.yaml 2024-07-23 15:46:24 +04:00
GitHub Action 2fe9471d8b Auto Template Signing [Sun Jul 21 08:33:01 UTC 2024] 🤖 2024-07-21 08:33:02 +00:00
Dhiyaneshwaran f8f9f0a2bc
Merge pull request #10289 from kazet/utf16-fp3
DS_Store template had FPs on UTF-16 encoded HTML files
2024-07-21 14:00:32 +05:30
GitHub Action 84a2749594 Auto Template Signing [Wed Jul 17 10:57:58 UTC 2024] 🤖 2024-07-17 10:57:59 +00:00
Dhiyaneshwaran 2ed6b437eb
Merge pull request #10246 from niranc/adcs
Active Directory Certificate Services blind detection
2024-07-17 16:25:46 +05:30
Dhiyaneshwaran 211cbab5bb
minor-update 2024-07-16 11:35:25 +05:30
Dhiyaneshwaran 6c3391d67a
minor-update 2024-07-16 11:34:35 +05:30
pussycat0x 855a34aa73
Update and rename adcs-detect.yaml to http/exposures/files/adcs-detect.yaml 2024-07-16 00:06:18 +05:30
Krzysztof Zając 9096114553 DS_Store template had FPs on UTF-16 encoded HTML files 2024-07-15 17:27:55 +02:00
GitHub Action 82f1fb6bc1 Auto Template Signing [Mon Jul 15 12:38:37 UTC 2024] 🤖 2024-07-15 12:38:38 +00:00
Dhiyaneshwaran c35e112e5a
minor update 2024-07-15 17:48:16 +05:30
Icaro Torres 4ec59411ea
Create apache-ozone-conf.yaml
Detects if path /conf of Apache Ozone web application is exposed.
2024-07-14 15:15:18 -03:00
GitHub Action 42142d444f Auto Template Signing [Fri Jul 12 17:42:53 UTC 2024] 🤖 2024-07-12 17:42:54 +00:00
Ritik Chaddha dc5675a465
Fix FP ds-store-file.yaml 2024-07-12 22:55:13 +05:30
GitHub Action 3ddb02f044 Auto Template Signing [Thu Jul 11 17:28:50 UTC 2024] 🤖 2024-07-11 17:28:50 +00:00
Dhiyaneshwaran f93276bfcd
Merge pull request #10178 from omranisecurity/main
Create snoop-servlet-exposure.yaml
2024-07-11 22:56:37 +05:30
Ritik Chaddha 0e8dfa9c6d
Update snoop-servlet-exposure.yaml 2024-07-10 23:44:21 +05:30
GitHub Action 3dc7577b70 Auto Template Signing [Wed Jul 10 06:57:01 UTC 2024] 🤖 2024-07-10 06:57:02 +00:00
Dhiyaneshwaran 56c3dfce53
fix mapping 2024-07-10 12:22:14 +05:30
Dhiyaneshwaran 220cede8c8
Update jwk-json-leak.yaml 2024-07-10 12:19:34 +05:30
GitHub Action fc60f25889 Auto Template Signing [Wed Jul 10 06:10:27 UTC 2024] 🤖 2024-07-10 06:10:28 +00:00
Dhiyaneshwaran afdb42c3e4
severity update 2024-07-10 11:35:09 +05:30
Dhiyaneshwaran 53a76df487
Update jwk-json-leak.yaml 2024-07-09 22:49:26 +05:30
pussycat0x f327acd133
lint -fix 2024-07-09 22:25:44 +05:30
pussycat0x b35bd321f9
Create jwk-json-leak.yaml 2024-07-09 22:23:10 +05:30
GitHub Action 249e1a7aa1 Auto Template Signing [Thu Jul 4 08:12:38 UTC 2024] 🤖 2024-07-04 08:12:39 +00:00
Ritik Chaddha bf2160b48b
updated macthers& info 2024-07-04 13:17:56 +05:30
Mohammad Reza Omrani 806d45b62c
Update snoop-servlet-exposure.yaml
Severity change
2024-07-03 11:33:31 +03:30
Mohammad Reza Omrani 12d4df0e3a
Create snoop-servlet-exposure.yaml 2024-07-03 11:29:28 +03:30
Icaro Torres 48d25050a4
Create apache-pinot-config.yaml
Detects if path Appconfigs of Apache Pinot web application is exposed, getting internal information about the configuration made.
2024-07-02 15:16:56 -03:00
GitHub Action a9a5ea4c83 Auto Template Signing [Tue Jul 2 10:00:29 UTC 2024] 🤖 2024-07-02 10:00:30 +00:00
Dhiyaneshwaran 4561e3eb3a
Merge pull request #9757 from userdehghani/patch-003
Add sql server backup exposure
2024-07-02 15:28:04 +05:30
Dhiyaneshwaran bd1c10ca04
minor update 2024-07-02 15:25:15 +05:30
pussycat0x 1fcb946e3f
duplicate path 2024-07-01 15:46:18 +05:30
GitHub Action 060c2741cf Auto Template Signing [Mon Jul 1 05:41:36 UTC 2024] 🤖 2024-07-01 05:41:36 +00:00
Ritik Chaddha 68ab7e0d34
updated matcher 2024-06-29 16:18:40 +05:30
Dhiyaneshwaran b4ecb01feb
Create filestash-admin-config.yaml 2024-06-28 15:15:28 +05:30
GitHub Action 4ac9c21951 Auto Template Signing [Thu Jun 27 15:59:00 UTC 2024] 🤖 2024-06-27 15:59:01 +00:00
Ritik Chaddha fe7637a45a
Rename neo4j-neodash-configexposed.yaml to neo4j-neodash-config.yaml 2024-06-26 13:45:19 +05:30
Ritik Chaddha 968acaac28
updated matcher, extractor & info 2024-06-26 13:44:53 +05:30
Icaro Torres 3b02b45a00
Create neo4j-neodash-configexposed.yaml
Detects the file config.json from Neo4j Neodash web application, it contains information about DB connection with Neo4J.
2024-06-24 13:49:57 -03:00
GitHub Action 00c08b64f3 Auto Template Signing [Thu Jun 20 10:15:50 UTC 2024] 🤖 2024-06-20 10:15:51 +00:00
Ritik Chaddha aa4b48714d
Merge pull request #10082 from projectdiscovery/fix-fp-ftpconfig
Update ftpconfig.yaml
2024-06-20 14:58:24 +05:30
GitHub Action 307fe13419 Auto Template Signing [Thu Jun 20 09:04:17 UTC 2024] 🤖 2024-06-20 09:04:17 +00:00
Ritik Chaddha 8472835bcf
Fix FP cakephp-config.yaml 2024-06-20 14:28:13 +05:30
Dhiyaneshwaran 2c96d316d7
Update ftpconfig.yaml 2024-06-20 14:22:11 +05:30
GitHub Action 0e5edf2541 Auto Template Signing [Wed Jun 12 15:41:04 UTC 2024] 🤖 2024-06-12 15:41:05 +00:00
Dhiyaneshwaran c81308329a
fix-fp 2024-06-12 18:01:33 +05:30
GitHub Action 3d255ddfdd Auto Template Signing [Sat Jun 8 16:02:16 UTC 2024] 🤖 2024-06-08 16:02:18 +00:00
GitHub Action f559aeaeb9 TemplateMan Update [Fri Jun 7 10:04:28 UTC 2024] 🤖 2024-06-07 10:04:29 +00:00
GitHub Action d5f6cc197c Auto Template Signing [Sun Jun 2 16:37:05 UTC 2024] 🤖 2024-06-02 16:37:06 +00:00
Ritik Chaddha 0e72f04734
Fix FN django-variables-exposed.yaml 2024-06-02 12:07:16 +05:30
GitHub Action e7b61d6662 Auto Template Signing [Sat Jun 1 19:25:56 UTC 2024] 🤖 2024-06-01 19:25:57 +00:00
Dhiyaneshwaran 2d875681b9
Fix FP netrc 2024-06-01 23:14:36 +05:30
GitHub Action 01128069d3 Auto Template Signing [Tue May 28 14:45:20 UTC 2024] 🤖 2024-05-28 14:45:20 +00:00
pussycat0x 903a5daaa5
Merge pull request #9867 from N0el4kLs/wechat-exposure-2
Create wechat-secret-key.yaml
2024-05-28 20:13:03 +05:30
N0el4kLs af00205a07 create: wechat-secret-key.yaml 2024-05-24 01:22:25 +08:00
GitHub Action 6efa0ced6f Auto Template Signing [Thu May 23 12:26:48 UTC 2024] 🤖 2024-05-23 12:26:49 +00:00
GitHub Action 0c4bce54ae Auto Template Signing [Thu May 23 12:19:25 UTC 2024] 🤖 2024-05-23 12:19:25 +00:00
Ritik Chaddha 762b36a2a9
Merge pull request #9861 from projectdiscovery/pussycat0x-patch-13
Update kyan-credential-exposure.yaml
2024-05-23 17:48:04 +05:30
Ritik Chaddha 7895921867
Update kyan-credential-exposure.yaml 2024-05-23 17:45:15 +05:30
Ritik Chaddha d5c2203079
Update robomongo-credential.yaml 2024-05-23 17:44:44 +05:30
pussycat0x 2a36cb0922
Update kyan-credential-exposure.yaml 2024-05-23 17:34:29 +05:30
pussycat0x 33edf377cd
Update robomongo-credential.yaml 2024-05-23 17:33:57 +05:30
GitHub Action c536c55df8 Auto Template Signing [Thu May 23 05:49:19 UTC 2024] 🤖 2024-05-23 05:49:20 +00:00
pussycat0x e531e88478
Merge pull request #9838 from kazet/inreasing-severity
Increasing severity of elmah logs exposure that can lead to session hijacking
2024-05-23 11:17:07 +05:30
Krzysztof Zając fe388f7da9 Increasing severity of elmah logs exposure that can lead to session hijacking 2024-05-21 09:23:48 +02:00
M. Dehghani 935f507907
Update sql-server-dump.yaml 2024-05-11 13:55:21 +03:30
M. Dehghani f7c6047f13
Add sql server backup exposure 2024-05-11 13:48:32 +03:30
GitHub Action 2b6b55cdd9 Auto Template Signing [Mon May 6 16:41:31 UTC 2024] 🤖 2024-05-06 16:41:31 +00:00
Prince Chaddha 18ec2125a4
Update settings-php-files.yaml 2024-05-06 17:35:26 +05:30
GitHub Action 02f7ca3d98 Auto Template Signing [Tue Apr 23 10:06:08 UTC 2024] 🤖 2024-04-23 10:06:09 +00:00
Dhiyaneshwaran a55392d147
Merge pull request #9321 from Michal-Mikolas/htdeployment
.htdeployment - files tree cache file
2024-04-17 18:05:31 +05:30
Dhiyaneshwaran aea53a5dc3
Update and rename htdeployment.yaml to ht-deployment.yaml 2024-04-17 17:54:00 +05:30
GitHub Action 23b41faacf Auto Template Signing [Tue Apr 16 06:19:30 UTC 2024] 🤖 2024-04-16 06:19:31 +00:00
Dhiyaneshwaran 4f8d6b273b
Merge pull request #9567 from righettod/redfish_add
Add detection of Redfish API.
2024-04-16 11:41:29 +05:30
Ritik Chaddha 8040fc22f9
updated matchers 2024-04-15 13:23:59 +05:30
GitHub Action 362e3a389c Auto Template Signing [Fri Apr 12 10:58:46 UTC 2024] 🤖 2024-04-12 10:58:47 +00:00
Ice3man a63774c77e feat: convert paths with lots of elements to payloads 2024-04-12 16:01:51 +05:30
Dominique RIGHETTO a750137dc6
Add files via upload 2024-04-12 09:48:55 +02:00
GitHub Action fa3da9dffa Auto Template Signing [Thu Apr 11 06:41:10 UTC 2024] 🤖 2024-04-11 06:41:11 +00:00
Dhiyaneshwaran 8666201df8
minor update 2024-04-11 11:48:23 +05:30
Ritik Chaddha c80a6d4bca
Update and rename exposed-aspnet-soap-webservices-asmx.yaml to aspnet-soap-webservices-asmx.yaml 2024-04-11 10:36:12 +05:30
Dominique RIGHETTO 7828baaeba
Add files via upload 2024-04-09 16:39:16 +02:00
Prince Chaddha 51db5ea193 Revert "TemplateMan Update [Mon Apr 8 11:30:07 UTC 2024] 🤖"
This reverts commit 433dda4ae5.
2024-04-08 17:04:33 +05:30
GitHub Action 433dda4ae5 TemplateMan Update [Mon Apr 8 11:30:07 UTC 2024] 🤖 2024-04-08 11:30:08 +00:00
Prince Chaddha c25af29a62
Delete http/exposures/logs/php-debug-bar.yaml 2024-04-05 10:33:48 +05:30
Prince Chaddha 6ed631f48f
Updated matcher 2024-03-28 13:52:14 +05:30
GitHub Action a7c488e65f Auto Template Signing [Thu Mar 28 06:36:17 UTC 2024] 🤖 2024-03-28 06:36:17 +00:00
Dhiyaneshwaran 1f49a12db7
Merge pull request #9284 from Michal-Mikolas/deployment-ini
deployment.ini - configuration file with FTP credentials exposure
2024-03-28 12:04:01 +05:30
Ritik Chaddha 04c1d76fed
updated matchers 2024-03-28 00:19:28 +05:30
GitHub Action d62f95fce6 Auto Template Signing [Mon Mar 25 11:57:16 UTC 2024] 🤖 2024-03-25 11:57:17 +00:00
GitHub Action c491aa6724 TemplateMan Update [Sat Mar 23 09:28:19 UTC 2024] 🤖 2024-03-23 09:28:20 +00:00
Dhiyaneshwaran 0cd4e5a335
Update and rename drupal-install.yaml to drupal-install.yaml 2024-03-21 13:11:35 +05:30
pussycat0x b1b540179a
Update drupal-install.yaml 2024-03-21 13:08:19 +05:30
GitHub Action cbf2c2568d Auto Template Signing [Wed Mar 20 08:13:55 UTC 2024] 🤖 2024-03-20 08:13:55 +00:00
Dhiyaneshwaran f162560bc1
Merge pull request #9333 from Michal-Mikolas/generic-db
generic-db: Check for publicly accessible SQLite database files
2024-03-20 13:41:39 +05:30
Dhiyaneshwaran cc8ee3aa0f
minor update 2024-03-20 13:38:58 +05:30
Ritik Chaddha 6bd7a9e020
updated with path variable 2024-03-20 12:51:44 +05:30
Ritik Chaddha 717075e5b3
Update generic-db.yaml 2024-03-20 09:33:12 +05:30
GitHub Action 2ede6795a6 Auto Template Signing [Tue Mar 19 16:40:41 UTC 2024] 🤖 2024-03-19 16:40:42 +00:00
Prince Chaddha b9a4f8433e reverted bruteforce tags to fuzz 2024-03-19 20:50:31 +05:30
Michal Mikolas db3ccee4aa generic-db: Improved SQLite file signature matcher to match exactly beginning of the document. 2024-03-18 22:51:49 +01:00
Michal Mikolas d81a235f97 generic-db: Added more exact matchers to make sure the exposured file is really SQLite file. 2024-03-18 21:37:49 +01:00
Michal Mikolas 746631b37f generic-db: Added checking of SQLite database files exposure. 2024-03-13 13:12:00 +01:00
Michal Mikolas 23a968d819 htdeployment: Improved matchers, lowering false positive chance (by added negative '<html' condition). 2024-03-13 09:44:22 +01:00
Michal Mikolas ce388acf79 deployment-ini: Added 'FTP Deployment' configuration file exposure. 2024-03-12 17:39:09 +01:00
Michal Mikolas 457fe56c2f htdeployment: Added '.htdeployment' cache file exposure template. 2024-03-12 17:13:27 +01:00