nuclei-templates/http/exposures/tokens/google/fcm-server-key.yaml

24 lines
613 B
YAML

id: fcm-server-key
info:
name: FCM Server Key
author: absshax
severity: high
description: FCM Server Key is leaked.
reference:
- https://abss.me/posts/fcm-takeover
metadata:
max-request: 1
tags: exposure,token,google
http:
- method: GET
path:
- "{{BaseURL}}"
extractors:
- type: regex
part: body
regex:
- "AAAA[a-zA-Z0-9_-]{7}:[a-zA-Z0-9_-]{140}"
# digest: 4a0a004730450220753b5d4f38184793a46538bdebec46552fad86403dca43a361c7ff9c52f6533f022100a7d3a2e7bff814e3a6eb36030ab0b4b0a08e0725edcf415a2ea2c344660dfa07:922c64590222798bb761d5b6d8e72950