44 lines
1.0 KiB
YAML
44 lines
1.0 KiB
YAML
id: security-txt
|
||
|
||
info:
|
||
name: security.txt File
|
||
author: bad5ect0r,noraj
|
||
severity: info
|
||
description: File similar to robots.txt but intended to be read by humans wishing to contact a website’s owner about security issues. Often defines a security policy and contact details.
|
||
reference:
|
||
- https://securitytxt.org/
|
||
- https://community.turgensec.com/security-txt-progress-in-ethical-security-research/
|
||
metadata:
|
||
max-request: 2
|
||
shodan-query: http.securitytxt:contact http.status:200
|
||
tags: misc,generic
|
||
|
||
http:
|
||
- method: GET
|
||
path:
|
||
- "{{RootURL}}/.well-known/security.txt"
|
||
- "{{RootURL}}/security.txt"
|
||
|
||
stop-at-first-match: true
|
||
host-redirects: true
|
||
max-redirects: 2
|
||
matchers-condition: and
|
||
matchers:
|
||
- type: status
|
||
status:
|
||
- 200
|
||
|
||
- type: word
|
||
words:
|
||
- "Contact:"
|
||
|
||
- type: dsl
|
||
dsl:
|
||
- "len(body) <= 1024 && len(body) > 0"
|
||
|
||
extractors:
|
||
- type: regex
|
||
group: 1
|
||
regex:
|
||
- '(?mi)Contact:(.*)'
|