id: sequoiadb-default-login info: name: SequoiaDB Default Login author: dhiyaneshDk severity: high description: Searches for default admin credentials for the SequoiaDB application. tags: default-login,sequoiadb requests: - raw: - | POST / HTTP/1.1 Host: {{Hostname}} Accept: */* X-Requested-With: XMLHttpRequest Content-Type: application/x-www-form-urlencoded; charset=UTF-8 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 SdbLanguage: en cmd=login&user={{username}}&passwd={{md5(password)}} payloads: username: - admin password: - admin attack: pitchfork matchers-condition: and matchers: - type: status status: - 200 - type: dsl dsl: - contains(tolower(all_headers), 'sdbsessionid') - type: word part: body words: - '{ "errno": 0 }'