id: wpconfig-aws-keys info: name: AWS S3 keys Leak author: r12w4n severity: high tags: aws,s3,wordpress,disclosure requests: - method: GET path: - '{{BaseURL}}/wp-config.php-backup' - "{{BaseURL}}/%c0" matchers: - type: word words: - 'access-key-id' - 'secret-access-key' - 'DB_NAME' - 'DB_PASSWORD' condition: and part: body