38 lines
1.1 KiB
YAML
38 lines
1.1 KiB
YAML
id: beanstalk-service
|
|
|
|
info:
|
|
name: Beanstalk Service - Detect
|
|
author: pussycat0x
|
|
severity: info
|
|
description: |
|
|
Beanstalk is a simple, fast work queue. Its interface is generic, but was originally designed for reducing the latency of page views in high-volume web applications by running time-consuming tasks asynchronously.
|
|
reference:
|
|
- https://jhadiary.wordpress.com/2016/05/18/beanstalk-helping-commands/
|
|
metadata:
|
|
verified: true
|
|
max-request: 1
|
|
shodan-query: port:11300 "cmd-peek"
|
|
tags: network,beanstalk,detect,enum,tcp
|
|
tcp:
|
|
- inputs:
|
|
- data: "stats\r\n"
|
|
read: 8
|
|
|
|
host:
|
|
- "{{Hostname}}"
|
|
port: 11300
|
|
|
|
matchers:
|
|
- type: word
|
|
part: raw
|
|
words:
|
|
- "cmd-release"
|
|
- "cmd-peek"
|
|
condition: and
|
|
|
|
extractors:
|
|
- type: regex
|
|
name: stats
|
|
regex:
|
|
- '([a-z-A-Z: 0-9]+)'
|
|
# digest: 4a0a00473045022100905d5e394de22fac18b6c7427b595b4e5d3d0d488254778c2a52b40b4b555ff902207b36ce3bb7ec290b8ba40a3ca39d4742e3620bd4d81013dfebe89ed060617b04:922c64590222798bb761d5b6d8e72950 |