id: javascript-env info: name: JavaScript Environment Configuration - Detect author: pdp,geeknik severity: low description: Multiple common JavaScript environment configuration files were detected. metadata: max-request: 6 tags: javascript,config,exposure http: - method: GET path: - "{{BaseURL}}/env.js" - "{{BaseURL}}/env.development.js" - "{{BaseURL}}/env.production.js" - "{{BaseURL}}/env.test.js" - "{{BaseURL}}/env.dev.js" - "{{BaseURL}}/env.prod.js" matchers-condition: and matchers: - type: status status: - 200 - type: dsl dsl: - "contains(tolower(header), 'content-type: application/javascript')" - type: word part: body words: - "module.exports" - "const audience" - "const domain" - "NODE_ENV" - "LOG_LEVEL" - "TOKEN" - "KEY" - "PASSWORD" - "VERSION" condition: or - type: word part: body words: - "Bootstrap" - "jQuery" - "CSS TRANSITION SUPPORT" - "is_ad_blocked" condition: or negative: true # digest: 4a0a00473045022100a9ee7848b6f19497fa027fc8c3dfefe78a1507cc28df767170f0079f6bed16b5022001249ac9e9f1574d56185b94868c9fd9e0c6c2473d87de6502c97e3311d1a573:922c64590222798bb761d5b6d8e72950