id: gitlab-public-snippets info: name: GitLab public snippets author: pdteam severity: info reference: - https://gist.github.com/vysecurity/20311c29d879e0aba9dcffbe72a88b10 - https://twitter.com/intigriti/status/1375078783338876929 metadata: max-request: 2 shodan-query: http.title:"GitLab" tags: gitlab,exposure,misconfig http: - method: GET path: - "{{BaseURL}}/explore/snippets" - "{{BaseURL}}/-/snippets" matchers-condition: and matchers: - type: word words: - 'Snippets · Explore · GitLab' - type: status status: - 200 - type: word negative: true condition: or words: - "No snippets found" - "Nothing here." # digest: 4a0a00473045022100d3d16e25f81c5915fd935bc5a9f2de217900b3988053ddc746b166d136b9abad02206444d30ac13fe8d61db12c71315c963c9644b758eaa3a41e1d12ee3752a13223:922c64590222798bb761d5b6d8e72950