nuclei-templates/default-logins/flir/flir-ax8-default-credential...

41 lines
932 B
YAML

id: flir-default-credentials
info:
name: Flir Default Credentials
author: pikpikcu
severity: medium
tags: default-login,flir
requests:
- raw:
- |
POST /login/dologin HTTP/1.1
Host: {{Hostname}}
Content-Length: 35
Accept: */*
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip, deflate
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Connection: closen
user_name=admin&user_password=admin
matchers-condition: and
matchers:
- type: word
words:
- '"success"'
- type: dsl
dsl:
- contains(tolower(all_headers), 'text/html')
- contains(tolower(all_headers), 'phpsessid')
- contains(tolower(all_headers), 'showcameraid')
condition: and
- type: status
status:
- 200