nuclei-templates/http/technologies/sap/sap-netweaver-detect.yaml

50 lines
1.2 KiB
YAML

id: sap-netweaver-detect
info:
name: SAP NetWeaver ICM - Detect
author: randomstr1ng,righettod
severity: info
description: |
Detection of SAP NetWeaver ABAP Webserver or Java Application Server (ICM/ICF)
metadata:
verified: true
max-request: 1
shodan-query: http.favicon.hash:-266008933
fofa-query:
- "sap-server:"
- icon_hash=-266008933
product: content_server
vendor: sap
tags: sap,webserver,tech,detect
http:
- method: GET
path:
- "{{BaseURL}}"
redirects: true
max-redirects: 2
matchers-condition: or
matchers:
- type: word
part: header
words:
- "sap-server:"
- "SAP NetWeaver Application Server"
condition: or
case-insensitive: true
- type: word
part: body
words:
- "SAP NetWeaver Application Server"
- "SAP NetWeaver Developer Studio"
- "SAP Management Console"
condition: or
extractors:
- type: kval
part: header
kval:
- "server"
# digest: 4a0a00473045022100dcae9dbe7f0dec9581e10ae7a83c26fa48efb9af82bf831109eb07c2c1edb9af022004427cdbdc5cb0e5b7491543a35eb947adb9712ba3864d6c2c0e139b231355be:922c64590222798bb761d5b6d8e72950