id: ventrilo-config info: name: Ventrilo Configuration File author: geeknik severity: high description: | It discloses the AdminPassword and Password of the application. reference: - https://www.ventrilo.com/setup.php metadata: verified: true tags: ventrilo,config,exposure requests: - method: GET path: - "{{BaseURL}}/ventrilo_srv.ini" matchers-condition: and matchers: - type: word words: - "[Server]" - "Name" - "Phonetic" condition: and - type: word part: header words: - "text/plain" - type: status status: - 200