id: esmtprc-config info: name: eSMTP config disclosure author: geeknik severity: high reference: - https://linux.die.net/man/5/esmtprc tags: esmtp,config requests: - method: GET path: - "{{BaseURL}}/.esmtprc" matchers-condition: and matchers: - type: word part: header words: - "text/plain" - type: word part: body words: - "hostname" - "username" - "password" condition: and - type: status status: - 200