id: javascript-env info: name: JavaScript Environment Configuration - Detect author: pdp,geeknik severity: low description: Multiple common JavaScript environment configuration files were detected. metadata: max-request: 6 tags: javascript,config,exposure http: - method: GET path: - "{{BaseURL}}/env.js" - "{{BaseURL}}/env.development.js" - "{{BaseURL}}/env.production.js" - "{{BaseURL}}/env.test.js" - "{{BaseURL}}/env.dev.js" - "{{BaseURL}}/env.prod.js" matchers-condition: and matchers: - type: status status: - 200 - type: dsl dsl: - "contains(tolower(header), 'content-type: application/javascript')" - type: word part: body words: - "module.exports" - "const audience" - "const domain" - "NODE_ENV" - "LOG_LEVEL" - "TOKEN" - "KEY" - "PASSWORD" - "VERSION" condition: or - type: word part: body words: - "Bootstrap" - "jQuery" - "CSS TRANSITION SUPPORT" condition: or negative: true # digest: 4b0a00483046022100c66e0d26c9f5dacb3a779ea553725976bba992bb71b7a968aac70caa10290088022100b458316aee6b28e8e5f559a2c068007e9bff6ac925a5c7375d677ed449bdb4a7:922c64590222798bb761d5b6d8e72950