id: sftp-config-exposure info: name: SFTP Configuration File - Detect author: geeknik severity: high description: SFTP configuration file was detected. reference: - https://blog.sucuri.net/2012/11/psa-sftpftp-password-exposure-via-sftp-config-json.html - https://www.acunetix.com/vulnerabilities/web/sftp-ftp-credentials-exposure/ - https://codexns.io/products/sftp_for_sublime/settings classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cwe-id: CWE-200 metadata: verified: true max-request: 1 github-query: filename:sftp-config.json tags: sftp,config,exposure http: - method: GET path: - "{{BaseURL}}/sftp-config.json" matchers-condition: and matchers: - type: word words: - '"host":' - '"user":' - '"password":' - '"remote_path":' condition: and - type: status status: - 200 # digest: 4b0a00483046022100973188487bf2223e26bd4e61bcd03a94625378b9a118546feb5c98955b7a4844022100f1bb6683cad6b0dca4029de026b5de436821ae40dcab4380c86fb9b711cdc83e:922c64590222798bb761d5b6d8e72950