Commit Graph

670 Commits (68b02887afdb72c14e15ae4e72e1f702d0209d7a)

Author SHA1 Message Date
Muhammad Daffa c83d035fff
Seperate technology template (#3430)
* Edit magmi workflow

* Add some workflow template + edit some template

* Changing some templates

* minor update

* workflow matcher fixes

* tech update

* Seperate technology template

* Update metabase-panel.yaml

* Update lucee-detect.yaml

* Update oneblog-detect.yaml

* Update dolibarr-panel.yaml

* Update dolibarr-panel.yaml

* Update dolibarr-panel.yaml

* Update gespage-panel.yaml

* Update gespage-panel.yaml

* Update mautic-crm-panel.yaml

* Update kibana-panel.yaml

* Update metabase-panel.yaml

* Update home-assistant-detect.yaml

* Update jitsi-meet-detect.yaml

* Update lucee-detect.yaml

* Update gotmls-plugin-lfi.yaml

* Update and rename technologies/opencast-detect.yaml to exposed-panels/opencast-detect.yaml

* duplicate template - cves/2020/CVE-2020-11738.yaml

Co-authored-by: sandeep <sandeep@projectdiscovery.io>
Co-authored-by: Prince Chaddha <prince@projectdiscovery.io>
2021-12-31 17:57:46 +05:30
Muhammad Daffa 5c800a4ef7
Seperate technologies and exposed-panels templates (#3424)
* Edit magmi workflow

* Add some workflow template + edit some template

* Changing some templates

* minor update

* workflow matcher fixes

* tech update

Co-authored-by: sandeep <sandeep@projectdiscovery.io>
2021-12-27 10:31:53 +05:30
sandeep 0425b36e10 moving templates around 2021-11-28 03:39:10 +05:30
sandeep 6220525d3e Added Golang expvar Information Disclosure
Co-Authored-By: Luqman <9842995+luqmanhy@users.noreply.github.com>
2021-11-13 02:03:22 +05:30
Prince Chaddha c1ca75e84d
Create desktop-ini-exposure.yaml 2021-11-08 13:03:22 +05:30
sandeep 8c3f98c767 fixed invalid template syntax 2021-10-30 16:47:35 +05:30
Prince Chaddha 8e730ca455
Create dwsync-exposure.yaml 2021-10-27 00:25:22 +05:30
Prince Chaddha 9e16035488
Merge pull request #2939 from martincodes-de/template/sensitive-idea-folder-files
add  template for  .idea files with sensitive data
2021-10-25 15:16:17 +05:30
Prince Chaddha 918c437dee
Update idea-folder-exposure.yaml 2021-10-24 14:32:00 +05:30
Prince Chaddha bc7d6e10be
Create idea-logs-exposure.yaml 2021-10-24 14:25:40 +05:30
Prince Chaddha 62643edb22
Update idea-folder-exposure.yaml 2021-10-24 14:23:37 +05:30
Prince Chaddha fc39fdd2f7
Update idea-folder-exposure.yaml 2021-10-21 19:29:49 +05:30
Prince Chaddha 709f6edbf7
Merge pull request #2948 from dahse89/add-config-symfony-security-config
Add Symfony Security Config Expose Template
2021-10-21 19:21:16 +05:30
Prince Chaddha 197c550fce
Update symfony-security-config.yaml 2021-10-21 19:19:21 +05:30
Prince Chaddha 9f197e6bf2
Merge pull request #2947 from sbani/php-errors
Merge PHP Errors Templates
2021-10-21 16:28:51 +05:30
Prince Chaddha 09d143b885
Update and rename .idea-folder-with-sensitive-files.yaml to idea-folder-exposure.yaml 2021-10-21 16:10:24 +05:30
Sufijen Bani ac9f713d97 Merge PHP Errors Templates
There was an extra error template for PHP warnings although there was
another template holding that already.

The status code check (500) is a step that would make sense for all of
the checks. This is not limited to warnings. Though I think that error
code 500 shrinks the result set too much in this case. That's why I
would leave it out.
2021-10-21 10:46:04 +02:00
Prince Chaddha a1be6ff566
Merge pull request #2945 from sbani/logs-folder
Add Deeper Search for Access Logs
2021-10-21 14:13:54 +05:30
Philipp Dahse fe4e6b8246 Add Symfony Security Config Expose Template
Symfony security contain information about used encryption algorithms and list which routes are protected
2021-10-21 10:33:56 +02:00
Sufijen Bani 378a682a5e Enhance Text Matching in Error Logs
Some words are missing that normally indicate that this is an error log.
2021-10-21 09:52:09 +02:00
Sufijen Bani 6d28009f5e Add Deeper Search for Access Logs
Search access logs in more folders. This happens for error logs too.
2021-10-21 09:42:50 +02:00
Sandeep Singh 5d6be591a0
Merge pull request #2934 from sbani/guntfile
Add Gruntfile Expose Test
2021-10-21 04:22:49 +05:30
sandeep cda7245de9 misc update 2021-10-21 04:21:52 +05:30
Sandeep Singh 00b0b7ecd0
Merge pull request #2936 from FlorianMaak/master
Add jetbrains datasource exposure check
2021-10-21 04:13:38 +05:30
Sandeep Singh 06b38542ff
Update jetbrains-datasources.yaml 2021-10-21 04:11:30 +05:30
martincodes 5f7519a89a add template for .idea files with sensitive data 2021-10-20 22:13:41 +02:00
Geeknik Labs ccc026ac70
Update github-workflows-disclosure.yaml
Might expose a SNYK_TOKEN
2021-10-20 13:44:17 -05:00
Florian Maak ecdb28d826 Add jetbrains datasource exposure check 2021-10-20 19:14:25 +02:00
Sufijen Bani 9ded2fcccf Add Gruntfile Expose Test
Gruntfile can include secrets or other information that helps find
further vulnerabilities.
2021-10-20 19:05:54 +02:00
Prince Chaddha 0152a2c355
Merge pull request #2917 from geeknik/patch-36
Create prometheus-config-endpoint.yaml
2021-10-19 22:28:09 +05:30
Prince Chaddha e2a074730e
Merge pull request #2919 from geeknik/patch-37
Create prometheus-flags-endpoint.yaml
2021-10-19 22:27:39 +05:30
Prince Chaddha c0857e0ab6
Merge pull request #2920 from geeknik/patch-38
Create prometheus-targets-endpoint.yaml
2021-10-19 22:27:23 +05:30
Prince Chaddha 8a69822285
Update prometheus-config-endpoint.yaml 2021-10-19 22:26:52 +05:30
Prince Chaddha 1d70ac6ccb
Update prometheus-flags-endpoint.yaml 2021-10-19 22:26:31 +05:30
Prince Chaddha a25a9f3020
Update prometheus-targets-endpoint.yaml 2021-10-19 22:25:44 +05:30
Prince Chaddha 6d13118df6
Update prometheus-targets-endpoint.yaml 2021-10-19 20:35:34 +05:30
Prince Chaddha 2893847959
Update prometheus-flags-endpoint.yaml 2021-10-19 20:34:13 +05:30
Prince Chaddha 8d36ebe1d6
Update prometheus-config-endpoint.yaml 2021-10-19 20:32:48 +05:30
Prince Chaddha 10c2314367
Update prometheus-flags-endpoint.yaml 2021-10-19 20:32:37 +05:30
Prince Chaddha 7016e71473
Update prometheus-config-endpoint.yaml 2021-10-19 20:27:46 +05:30
Philippe Delteil 667ee78cb5
Update sensitive-storage-exposure.yaml 2021-10-18 23:09:27 -03:00
Geeknik Labs c9f2ef68ed
Update prometheus-config-endpoint.yaml 2021-10-18 17:28:10 -05:00
Geeknik Labs eac799774d
Update prometheus-flags-endpoint.yaml 2021-10-18 14:36:49 -05:00
Geeknik Labs 86a8332187
Update prometheus-flags-endpoint.yaml
adding regex extractor to alert if `optional` Prometheus management API is enabled as per the linked reference article. 👍🏻
2021-10-18 13:51:11 -05:00
Geeknik Labs 72805491d0
Create prometheus-targets-endpoint.yaml 2021-10-18 13:44:55 -05:00
Geeknik Labs 0f20469e96
Update prometheus-flags-endpoint.yaml 2021-10-18 13:43:36 -05:00
Geeknik Labs a8a063d14c
Create prometheus-flags-endpoint.yaml 2021-10-18 13:36:27 -05:00
Geeknik Labs c7efad4b58
Create prometheus-config-endpoint.yaml 2021-10-18 13:35:04 -05:00
opp? aec00d0d11
add more tags to keycloak json file template 2021-10-18 13:38:04 -03:00
sandeep 233ca1fef9 improved regex to handle more cases 2021-10-13 11:53:02 +05:30
Geeknik Labs a476fc9ca4
Update laravel-env.yaml
added case insensitivity to the regex matcher
2021-10-08 11:30:44 -05:00
Sandeep Singh 4d52f354ee
Merge pull request #2853 from pdelteil/patch-66
Update zend-config-file.yaml
2021-10-08 19:15:45 +05:30
sandeep 8960821db1 Update zend-config-file.yaml 2021-10-08 19:15:26 +05:30
Philippe Delteil 976f695929
Update zend-config-file.yaml 2021-10-08 03:53:52 -03:00
Geeknik Labs 589a1c16ee
Update github-workflows-disclosure.yaml 2021-10-07 16:51:45 -05:00
Geeknik Labs 793f3474b0
Update github-workflows-disclosure.yaml
Add new paths
2021-10-07 16:50:57 -05:00
Prince Chaddha 5b5e764b48
Merge pull request #2787 from mr-rizwan-syed/master
wp-config-file and aws-s3-access-key-leak
2021-10-05 18:25:04 +05:30
Prince Chaddha 5c4dd11b6b
Rename misconfiguration/wpconfig-aws-keys.yaml to exposures/configs/wpconfig-aws-keys.yaml 2021-10-05 18:20:43 +05:30
Prince Chaddha 56c8c36ef2
Merge pull request #2802 from geeknik/patch-32
Create axiom-digitalocean-key-exposure.yaml
2021-10-05 09:34:53 +05:30
Prince Chaddha 74f0620a9f
Update axiom-digitalocean-key-exposure.yaml 2021-10-04 22:09:12 +05:30
sandeep 5618fcaa7e Update axiom-digitalocean-key-exposure.yaml 2021-10-02 04:41:32 +05:30
sandeep e08ccf85db adding missing condition 2021-10-02 04:37:10 +05:30
Geeknik Labs 2327224260
Update axiom-digitalocean-key-exposure.yaml 2021-10-01 13:22:35 -05:00
Geeknik Labs bdbf73cd34
Update tugboat-config-exposure.yaml 2021-10-01 13:21:58 -05:00
Geeknik Labs ec88d62ad4
Create axiom-digitalocean-key-exposure.yaml
create axiom-digitalocean-key-exposure.yaml
2021-10-01 13:20:23 -05:00
Geeknik Labs c05df76ed2
Create tugboat-config-exposure.yaml
Create tugboat-config-exposure.yaml
2021-10-01 13:13:35 -05:00
Prince Chaddha 807920c0ac clean-up 2021-09-21 17:16:53 +05:30
Prince Chaddha cf0edc490a
Rename crossdomin-xml.yaml to crossdomain-xml.yaml 2021-09-20 23:28:06 +05:30
Geeknik Labs 8eea40d15c
Update php-warning.yaml
Additional status matcher
2021-09-17 13:07:59 -05:00
Geeknik Labs 2cce7831a6
Update php-warning.yaml
Fixes #2705
2021-09-17 13:04:07 -05:00
Prince Chaddha ab4e6a4dd6
Merge pull request #2696 from DhiyaneshGeek/master
New Templates Added
2021-09-17 16:29:58 +05:30
Prince Chaddha 5858e3a01c
Update and rename exposures/logs/database-error.yaml to misconfiguration/database-error.yaml 2021-09-17 13:33:54 +05:30
Prince Chaddha 156daddde0
Update phpinfo.yaml 2021-09-17 13:20:06 +05:30
Prince Chaddha 0b7c12951c
Update php-warning.yaml 2021-09-17 13:13:40 +05:30
Prince Chaddha 52162716e5
Update and rename exposures/logs/zabbix-error.yaml to misconfiguration/zabbix-error.yaml 2021-09-17 13:00:35 +05:30
Prince Chaddha a3ce6426f6
Update database-error.yaml 2021-09-17 12:46:35 +05:30
Dhiyaneshwaran 24b40f5f5d
Update phpinfo.yaml 2021-09-17 08:19:28 +05:30
Dhiyaneshwaran 8554474fd2
Create database-error.yaml 2021-09-17 08:14:18 +05:30
Dhiyaneshwaran 4959b99a7d
Create zabbix-error.yaml 2021-09-17 08:11:38 +05:30
Dhiyaneshwaran 320c973288
Create php-warning.yaml 2021-09-17 08:07:18 +05:30
Sandeep Singh f47c4da9e8
Merge pull request #2694 from geeknik/geeknik-patch-1
MIscellaneous updates
2021-09-17 02:22:26 +05:30
sandeep f0cac598cb misc update 2021-09-17 02:18:04 +05:30
Geeknik Labs 56590675cf
Update squid-analysis-report-generator.yaml 2021-09-16 15:16:26 -05:00
Geeknik Labs 95664dfc18
Update credentials-disclosure.yaml 2021-09-16 15:13:12 -05:00
Geeknik Labs 42e644b7fd
Update bower-json.yaml 2021-09-16 15:11:24 -05:00
Dhiyaneshwaran cb80cbb537
Create dsm-terminator-error.yaml 2021-09-14 22:46:01 +05:30
Dhiyaneshwaran c225428932
Create struts-problem-report.yaml 2021-09-14 22:30:18 +05:30
Dhiyaneshwaran be24688a48
Create error-processing.yaml 2021-09-14 21:49:36 +05:30
sandeep bd24dc198e Coverage for all templates using tags 2021-09-09 19:08:13 +05:30
sandeep 609705f676 removed extra headers not required for template 2021-09-08 17:47:19 +05:30
sullo ef1f7c5e92 Updates across many templates for clarity, spelling, and grammar. 2021-09-05 17:13:45 -04:00
Sandeep Singh cdd022c29d
Merge pull request #2550 from projectdiscovery/adding-sfm
Added stop-at-first-match in applicable templates
2021-09-02 23:09:21 +05:30
sandeep 8b37808730 misc update 2021-09-02 22:57:55 +05:30
Geeknik Labs 5414f9a618
Update general-tokens.yaml 2021-09-02 10:36:46 -05:00
sandeep c266084621 Added stop-at-first-match in applicable templates 2021-09-02 17:29:10 +05:30
Sandeep Singh 0d1d2b3b1b
Merge pull request #2512 from DhiyaneshGeek/master
Webpack Sourcemap Disclosure
2021-09-02 00:34:56 +05:30
sandeep aeac5bbec3 misc update 2021-08-31 01:03:44 +05:30
Sandeep Singh 7608386bb3
Update dbeaver-credentials.yaml 2021-08-30 15:24:34 +05:30
Philippe Delteil 7a9093c8a7
Update dbeaver-credentials.yaml
Change solve the false positives due to  {} (empty response)

Example

nuclei -t nuclei-templates/exposures/configs/dbeaver-credentials.yaml -u https://lbs.map.qq.com
2021-08-30 02:55:35 -04:00
sandeep 8c1de71ec9 wip - update 2021-08-29 18:50:29 +05:30
Dhiyaneshwaran 6bade73727
Create webpack-sourcemap-disclosure.yaml 2021-08-29 17:13:44 +05:30
forgedhallpass a4250b8f2f Merge remote-tracking branch 'origin' into dynamic_attributes 2021-08-26 15:04:14 +03:00
sandeep 39ce8ee5b2 misc updates 2021-08-26 15:03:35 +05:30
Douglas Santos 1685ce08b0 Apache Axis 1 and 2 templates 2021-08-26 02:11:02 +00:00
sandeep ee49f89109 misc update 2021-08-26 03:51:35 +05:30
sandeep 0d3d9a37d9 misc update 2021-08-26 03:47:32 +05:30
Sandeep Singh ce1daa8c80
Update glpi-status-ldap-domain-disclosure.yaml 2021-08-26 03:42:53 +05:30
Douglas Santos 22d0b35775 GLPI detection, status and telemetry exposure 2021-08-25 21:55:22 +00:00
forgedhallpass 110f9c9ddd Merge remote-tracking branch 'origin' into dynamic_attributes 2021-08-24 20:38:11 +03:00
sandeep ae0aabd905 misc update 2021-08-24 02:50:14 +05:30
forgedhallpass a124e393b4 Merge remote-tracking branch 'origin' into dynamic_attributes 2021-08-23 19:15:14 +03:00
Prince Chaddha 647d27925a
Merge pull request #2426 from projectdiscovery/generic
Templates by geeknik
2021-08-23 19:55:32 +05:30
Prince Chaddha b5ec33e4c0
Update dockercfg-config.yaml 2021-08-23 19:52:39 +05:30
Sandeep Singh 1def46a72e
Update firebase-config-exposure.yaml 2021-08-23 15:11:10 +05:30
Sandeep Singh 93894d5b8c
Update dbeaver-credentials.yaml 2021-08-23 15:09:33 +05:30
Sandeep Singh 43fe743729
Update and rename dockercfg.yaml to dockercfg-config.yaml 2021-08-23 15:07:02 +05:30
sandeep e160acb481 misc updates 2021-08-20 16:37:22 +05:30
forgedhallpass 77103bc629 Satisfying the linter (all errors and warnings)
* whitespace modifications only
2021-08-19 17:44:46 +03:00
forgedhallpass 002e8db616 Moved the "vendor" custom attribute under reference
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 17:00:46 +03:00
forgedhallpass f55d6b75e1 Removed pipe (|) character from references, because the structure requires it to be a string slice, not a string
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:59:12 +03:00
forgedhallpass 7b29be739e Merge branch 'master' into dynamic_attributes 2021-08-19 16:23:26 +03:00
forgedhallpass 0b432b341b Added comments with URLs under the "references" field
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 16:15:35 +03:00
forgedhallpass e68d15ab63 Fixed mistakes/typos in the templates.
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-19 15:30:14 +03:00
Prince Chaddha f65a78bb5c
Create firebase-config-exposure.yaml 2021-08-19 16:56:13 +05:30
Prince Chaddha acbacf339d
Update dockercfg.yaml 2021-08-19 16:48:50 +05:30
Prince Chaddha 2e4c8e22f2
Create dockercfg.yaml 2021-08-19 16:47:22 +05:30
Prince Chaddha d7e7c39982
Update dbeaver-credentials.yaml 2021-08-19 16:34:32 +05:30
Prince Chaddha c980eea40b
Create dbeaver-credentials.yaml 2021-08-19 16:32:09 +05:30
Prince Chaddha 760af33ce9
Update db-schema.yaml 2021-08-19 15:03:10 +05:30
Prince Chaddha 4c27b5d5ee
Create db-schema.yaml 2021-08-19 15:00:00 +05:30
Prince Chaddha 20e66005b7
Update and rename couchbase-buckets-rest-api.yaml to couchbase-buckets-api.yaml 2021-08-19 14:57:01 +05:30
Prince Chaddha d10c81b2ba
Create couchbase-buckets-rest-api.yaml 2021-08-19 14:56:35 +05:30
Prince Chaddha 4d9bd2d13b
Update zend-config-file.yaml 2021-08-19 14:27:45 +05:30
forgedhallpass cdf9451158 Removed pipe (|) character from references, because the structure requires it to be a string slice, not a string
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-18 14:44:27 +03:00
forgedhallpass 4c920b2552 Rename "references" to "reference" to match the expected template info structure
Related nuclei tickets:
* #259 - dynamic key-value field support for template information
* #940 - new infos in template
* #834
* RES-84
2021-08-18 14:29:20 +03:00
Sandeep Singh 5b17aea895
Merge pull request #2388 from geeknik/patch-17
Update general-tokens.yaml
2021-08-17 22:34:03 +05:30
Geeknik Labs 5c994cfad6
Update general-tokens.yaml
I believe this might work.
2021-08-17 11:52:31 -05:00
sandeep 9850ced093 strict matchers 2021-08-17 22:11:28 +05:30
Prince Chaddha 5e55dc1e24
Create django-debug-exposure.yaml 2021-08-17 17:37:57 +05:30
sandeep 51b15ff0d4 severity update 2021-08-14 17:28:23 +05:30
sandeep ffcfaa5cb1 minor update 2021-08-14 16:51:20 +05:30
Prince Chaddha 739622c7ab
Merge pull request #2394 from gabrielb3lmont/exposures_templates
Added crossdomain-xml Template
2021-08-14 15:46:53 +05:30
Prince Chaddha 77f59df9c8
Update crossdomin-xml.yaml 2021-08-14 15:45:34 +05:30
Prince Chaddha d13bc82a2e
Update crossdomin-xml.yaml 2021-08-14 14:42:16 +05:30
Prince Chaddha 3183242eb3
Merge pull request #2366 from pikpikcu/patch-250
Create iceflow-vpn-disclosure
2021-08-14 14:37:09 +05:30
Prince Chaddha 9c51bc0abb
Update iceflow-vpn-disclosure.yaml 2021-08-14 14:35:41 +05:30
Prince Chaddha 6b65897dd9
Update iceflow-vpn-disclosure.yaml 2021-08-14 14:30:29 +05:30
LogicalHunter e6d9a1ec90 Fixed crossdomain-xml template 2021-08-13 11:25:10 -07:00
LogicalHunter 126e27e3b2 Added crossdomain-xml Template 2021-08-13 10:49:41 -07:00
Geeknik Labs c9daa11bd8
Update general-tokens.yaml 2021-08-12 09:54:57 -05:00