nuclei-templates/exposed-panels/sophos-fw-version-detect.yaml

28 lines
625 B
YAML

id: sophos-fw-version-detect
info:
name: Sophos Firewall version detection
author: organiccrap
severity: info
tags: panel,sophos
requests:
- method: GET
path:
- "{{BaseURL}}/webconsole/webpages/login.jsp"
- "{{BaseURL}}/userportal/webpages/myaccount/login.jsp"
matchers-condition: and
matchers:
- type: word
words:
- "<title>Sophos</title>"
- type: regex
part: body
regex:
- "(\\d{2}.\\d{1,2}.\\d{1,2}.\\d{2,3})"
extractors:
- type: regex
part: body
regex:
- "(\\d{2}.\\d{1,2}.\\d{1,2}.\\d{2,3})"