nuclei-templates/http/takeovers/worksites-takeover.yaml

29 lines
701 B
YAML

id: worksites-takeover
info:
name: worksites takeover detection
author: melbadry9
severity: high
reference:
- https://blog.melbadry9.xyz/dangling-dns/xyz-services/ddns-worksites
metadata:
max-request: 1
tags: takeover
http:
- method: GET
path:
- "{{BaseURL}}"
matchers-condition: and
matchers:
- type: dsl
dsl:
- Host != ip
- type: regex
regex:
- "(?:Company Not Found|you’re looking for doesn’t exist)"
# digest: 490a0046304402203b75d6e58720c807194ef6a62552d097e7de60926ca2fae96db9e4873ecc389202203d39a42e1be2e0377a78f759b510de5b797181f5ca3027eb3c28e77913d34e62:922c64590222798bb761d5b6d8e72950