nuclei-templates/http/token-spray/api-google-drive.yaml

29 lines
789 B
YAML

id: api-google-drive
info:
name: Google Drive API Test
author: geeknik
severity: info
reference:
- https://developers.google.com/drive/api/guides/about-sdk
metadata:
max-request: 1
tags: token-spray,google,drive,intrusive
self-contained: true
http:
- raw:
- |
GET https://www.googleapis.com/drive/v3/files/{{randstr}}.txt/%3fkey={{token}}&supportsAllDrives=true HTTP/1.1
Referer: {{referer}}
Content-Type:application/json
matchers:
- type: word
part: body
words:
- 'File not found: {{randstr}}.txt.'
# digest: 4b0a00483046022100f3d2e430755236cb5354472588b85c1caa009551fffb628d51c8321a8c900fd3022100c756303eff99e074d92d5f4b223322b94572b1515b741fee9473fa14cc0984ef:922c64590222798bb761d5b6d8e72950