id: surveysparrow-takeover info: name: SurveySparrow takeover detection author: philippedelteil severity: high description: SurveySparrow takeover was detected. reference: - https://github.com/EdOverflow/can-i-take-over-xyz/issues/281 metadata: max-request: 1 tags: takeover,surveysparrow http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: dsl dsl: - Host != ip - type: word words: - "Account not found." - "ouch!" - "SurveySparrow" condition: and # digest: 4b0a00483046022100ff4d63e33b67fb2ff21325b11008922a19e3bad15fead71e40a2168fef4b34e3022100bb737388806f6773e498a74f759fe708048d904fe6600f668ba726af4f883332:922c64590222798bb761d5b6d8e72950