id: chatgpt-web-unauth info: name: ChatGPT Web - Unauthorized Access author: SleepingBag945 severity: high metadata: verified: true max-request: 1 fofa-query: app="Chatgpt-web" tags: chatgpt,unauth,misconfig http: - raw: - | POST /api/session HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {} matchers-condition: and matchers: - type: word part: body words: - '"status":"Success"' - '"auth":false' - 'ChatGPTAPI' condition: and - type: word part: header words: - "application/json" - type: status status: - 200 # digest: 490a00463044022025e67a1afa68039433f2eeb68afb01b6cefcf700d2976a83d01845f87a2cfcf902204c852c5d7b15d180a10864001521e703eddde47ab3722d0090b6bfbf62f4b3f5:922c64590222798bb761d5b6d8e72950