id: surveysparrow-takeover info: name: SurveySparrow takeover detection author: philippedelteil severity: high description: SurveySparrow takeover was detected. reference: - https://github.com/EdOverflow/can-i-take-over-xyz/issues/281 metadata: max-request: 1 tags: takeover,surveysparrow http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: dsl dsl: - Host != ip - type: word words: - "Account not found." - "ouch!" - "SurveySparrow" condition: and extractors: - type: dsl dsl: - "resolve(Host, 'cname')" # digest: 4a0a00473045022100a5d612e8edd2e7e0be76838eafb7fc5255b09b098f6a5984d80674fae34dbec702202ded396f540ff22e864c5c7584feea766ed7c012d225ff0b6854e487d4368e6d:922c64590222798bb761d5b6d8e72950