id: composer-auth-json info: name: Composer-auth Json File Disclosure author: DhiyaneshDK severity: low reference: https://www.exploit-db.com/ghdb/5768 metadata: verified: true max-request: 2 google-query: intext:"index of /" ".composer-auth.json" tags: exposure,devops,files http: - method: GET path: - "{{BaseURL}}/.composer-auth.json" - "{{BaseURL}}/vendor/webmozart/assert/.composer-auth.json" stop-at-first-match: true matchers-condition: and matchers: - type: word words: - 'github-oauth' - 'github.com' condition: and - type: status status: - 200 # digest: 4b0a00483046022100d76d9b95b4179ee9848fd6229ce2055e7cdbc135ff0660bea2178d92df0137fa022100900c797e939708bc18c20d613d38edd938e0ce43d8908a8568583e6c660560bb:922c64590222798bb761d5b6d8e72950