id: zip-backup-files info: name: Compressed Backup File - Detect author: toufik-airane,dwisiswant0,ffffffff0x,pwnhxl severity: medium description: Multiple compressed backup files were detected. classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cwe-id: CWE-200 metadata: max-request: 625 tags: exposure,backup http: - method: GET path: - "{{BaseURL}}/{{FILENAME}}.{{EXT}}" attack: clusterbomb payloads: FILENAME: - "{{FQDN}}" # www.example.com - "{{RDN}}" # example.com - "{{DN}}" # example - "{{SD}}" # www - "{{date_time('%Y')}}" # 2023 - "ROOT" # tomcat - "wwwroot" - "htdocs" - "www" - "html" - "web" - "webapps" - "public" - "public_html" - "uploads" - "website" - "api" - "test" - "app" - "backup" - "bin" - "bak" - "old" - "Release" - "inetpub" EXT: - "7z" - "bz2" - "gz" - "lz" - "rar" - "tar.gz" - "tar.bz2" - "xz" - "zip" - "z" - "tar.z" - "db" - "sqlite" - "sqlitedb" - "sql.7z" - "sql.bz2" - "sql.gz" - "sql.lz" - "sql.rar" - "sql.tar.gz" - "sql.xz" - "sql.zip" - "sql.z" - "sql.tar.z" - "war" max-size: 500 # Size in bytes - Max Size to read from server response matchers-condition: and matchers: - type: binary binary: - "377ABCAF271C" # 7z - "314159265359" # bz2 - "53514c69746520666f726d6174203300" # SQLite format 3. - "1f8b" # gz tar.gz - "526172211A0700" # rar RAR archive version 1.50 - "526172211A070100" # rar RAR archive version 5.0 - "FD377A585A0000" # xz tar.xz - "1F9D" # z tar.z - "1FA0" # z tar.z - "4C5A4950" # lz - "504B0304" # zip condition: or part: body - type: regex regex: - "application/[-\\w.]+" part: header - type: status status: - 200