id: atom-sync-remote info: name: Atom Synchronization Exposure author: geeknik severity: high description: | It discloses username and password created by remote-sync for Atom, contains FTP and/or SCP/SFTP/SSH server details and credentials metadata: verified: true max-request: 1 tags: atom,exposure,config,files http: - method: GET path: - "{{BaseURL}}/.remote-sync.json" matchers-condition: and matchers: - type: word part: body words: - '"hostname":' - '"username":' condition: and - type: word part: body words: - "passphrase" - "password" condition: or - type: word part: header words: - "application/json" - type: status status: - 200 # digest: 490a0046304402203c2cdc6eb2e5ba53413df0c22072777c74efcfb1df85e2c762933675ab9fa19d0220297af89ee6df02e54dd45dac6fd1e7faa45e985077252ebac613860a3c7a2faf:922c64590222798bb761d5b6d8e72950