id: netrc info: name: Netrc - Config File Discovery author: geeknik severity: high description: Netrc configuration file was discovered. reference: - https://www.gnu.org/software/inetutils/manual/html_node/The-_002enetrc-file.html tags: netrc,config,exposure requests: - method: GET path: - "{{BaseURL}}/.netrc" - "{{BaseURL}}/_netrc" matchers-condition: and matchers: - type: status status: - 200 - type: regex regex: - "machine [0-9A-Za-z](?:(?:[0-9A-Za-z]|-){0,61}[0-9A-Za-z])?(?:\\.[0-9A-Za-z](?:(?:[0-9A-Za-z]|-){0,61}[0-9A-Za-z])?)*\\.?" - type: word words: - "login " - "password " condition: and extractors: - type: regex part: body regex: - "machine [0-9A-Za-z](?:(?:[0-9A-Za-z]|-){0,61}[0-9A-Za-z])?(?:\\.[0-9A-Za-z](?:(?:[0-9A-Za-z]|-){0,61}[0-9A-Za-z])?)*\\.?" # Enhanced by mp on 2022/07/15