id: sogo-detect info: name: SOGo Detect author: righettod severity: info description: This template will detect a running SOGo instance reference: - https://www.sogo.nu/ classification: cpe: cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:* metadata: verified: true max-request: 2 vendor: alinto product: sogo shodan-query: http.title:"SOGo" tags: sogo,tech http: - method: GET path: - "{{BaseURL}}" - "{{BaseURL}}/SOGo" stop-at-first-match: true host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word part: body words: - 'content="SOGo Web Interface"' - 'sg-default="SOGo' condition: or - type: status status: - 200 # digest: 4a0a00473045022100e1af9285ba85f91239403e574233a1e1bcabf37d8f63f8aa65729cce7237bfb7022008e4833d3a8c629c02c70eb547f452c8d97a80267e10f43845f99f4d9ea3cd79:922c64590222798bb761d5b6d8e72950