id: grafana-detect info: name: Grafana Login Panel - Detect author: organiccrap,AdamCrosser,bhutch severity: info description: Grafana login panel was detected. classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cwe-id: CWE-200 cpe: cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* metadata: max-request: 2 vendor: grafana product: grafana shodan-query: - title:"Grafana" - cpe:"cpe:2.3:a:grafana:grafana" - http.title:"grafana" category: devops fofa-query: - title="grafana" - app="grafana" google-query: intitle:"grafana" tags: panel,grafana,detect http: - method: GET path: - "{{BaseURL}}/login" - "{{BaseURL}}/graph/login" stop-at-first-match: true matchers: - type: word part: body words: - "Grafana" extractors: - type: regex name: version part: body group: 1 regex: - '\"version\"\:\"([0-9.]+)\"}' - '\"subTitle\":\"Grafana v([0-9.]+)' - type: kval kval: - version # digest: 490a0046304402203e8860b188f88035cd6d396eb8aa8ef0f43eefc67e36438b8dd034c44ce11e6b0220278a274edaacbcf855169ded447ae516dd871ba72388a58eb61e4cbd519459ec:922c64590222798bb761d5b6d8e72950