111 lines
4.0 KiB
YAML
111 lines
4.0 KiB
YAML
id: favicon-detection
|
|
|
|
info:
|
|
name: favicon
|
|
author: un-fmunozs
|
|
severity: info
|
|
|
|
# 946,0488faca4c19046b94d07c3ee83cf9d6,springboot
|
|
# 2336,02f4db63a9cfb650c05ffd82956cbfd6,proxmox
|
|
# 21630,4644f2d45601037b8423d45e13194c93,tomcat
|
|
# 6518,3e7f8aa6768bba07751fe8570d7a244c,airwatch
|
|
# 30894,6eb4a43cb64c97f76562af703893c8fd,xampp
|
|
# 765,e16377344d2d52a15e735041b3eb2c5a,kibana
|
|
# 17542,e16377344d2d52a15e735041b3eb2c5a,jenkins
|
|
# 1150,6d2adf39ca320265830403dfc030033a,liferay
|
|
# 3638,59a0c7b6e4848ccdabcea0636efda02b,blogger
|
|
# 198,c6acedaff906029fc5455d9ec52c7f42,wordpress
|
|
# 5430,c291c057816f71ce15ba5c496f1a965a,wordpress
|
|
# 1611,f7e3d97f404e71d302b3239eef48d5f2,gitlab
|
|
# 6093,88717398db158e3330ce94fc1784e4a7,jira
|
|
# 2494,88717398db158e3330ce94fc1784e4a7,jira
|
|
|
|
requests:
|
|
- method: GET
|
|
path:
|
|
- "{{BaseURL}}/favicon.ico"
|
|
redirects: true
|
|
max-redirects: 3
|
|
matchers-condition: or
|
|
matchers:
|
|
- type: dsl
|
|
name: springboot
|
|
dsl:
|
|
- "len(body)==946 && status_code==200 && (\"0488faca4c19046b94d07c3ee83cf9d6\" == md5(body))"
|
|
- type: dsl
|
|
name: proxmox
|
|
dsl:
|
|
- "len(body)==2336 && status_code==200 && (\"02f4db63a9cfb650c05ffd82956cbfd6\" == md5(body))"
|
|
- type: dsl
|
|
name: tomcat
|
|
dsl:
|
|
- "len(body)==21630 && status_code==200 && (\"4644f2d45601037b8423d45e13194c93\" == md5(body))"
|
|
- type: dsl
|
|
name: airwatch
|
|
dsl:
|
|
- "len(body)==6518 && status_code==200 && (\"3e7f8aa6768bba07751fe8570d7a244c\" == md5(body))"
|
|
- type: dsl
|
|
name: blogger
|
|
dsl:
|
|
- "len(body)==3638 && status_code==200 && (\"59a0c7b6e4848ccdabcea0636efda02b\" == md5(body))"
|
|
- type: dsl
|
|
name: xampp
|
|
dsl:
|
|
- "len(body)==30894 && status_code==200 && (\"6eb4a43cb64c97f76562af703893c8fd\" == md5(body))"
|
|
- type: dsl
|
|
name: kibana
|
|
dsl:
|
|
- "len(body)==1150 && status_code==200 && (\"e16377344d2d52a15e735041b3eb2c5a\" == md5(body))"
|
|
- type: dsl
|
|
name: liferay
|
|
dsl:
|
|
- "len(body)==1150 && status_code==200 && (\"6d2adf39ca320265830403dfc030033a\" == md5(body))"
|
|
- type: dsl
|
|
name: jenkins
|
|
dsl:
|
|
- "len(body)==17542 && status_code==200 && (\"23e8c7bd78e8cd826c5a6073b15068b1\" == md5(body))"
|
|
- type: dsl
|
|
name: wordpress
|
|
dsl:
|
|
- "len(body)==198 && status_code==200 && (\"c6acedaff906029fc5455d9ec52c7f42\" == md5(body))"
|
|
- type: dsl
|
|
name: wordpress
|
|
dsl:
|
|
- "len(body)==5430 && status_code==200 && (\"c291c057816f71ce15ba5c496f1a965a\" == md5(body))"
|
|
- type: dsl
|
|
name: gitlab
|
|
dsl:
|
|
- "len(body)==1611 && status_code==200 && (\"f7e3d97f404e71d302b3239eef48d5f2\" == md5(body))"
|
|
- type: dsl
|
|
name: jira
|
|
dsl:
|
|
- "len(body)==6093 && status_code==200 && (\"88717398db158e3330ce94fc1784e4a7\" == md5(body))"
|
|
- type: dsl
|
|
name: jira
|
|
dsl:
|
|
- "len(body)==2494 && status_code==200 && (\"04d89d5b7a290334f5ce37c7e8b6a349\" == md5(body))"
|
|
- type: dsl
|
|
name: confluence
|
|
dsl:
|
|
- "len(body)==4259 && status_code==200 && (\"966e60f8eb85b7ea43a7b0095f3e2336\" == md5(body))"
|
|
- type: dsl
|
|
name: mobileiron
|
|
dsl:
|
|
- "len(body)==1734 && status_code==200 && (\"8a185957a6b153314bab3668b57f18f4\" == md5(body))"
|
|
- type: dsl
|
|
name: oracle
|
|
dsl:
|
|
- "len(body)==1150 && status_code==200 && (\"421e176ae0837bcc6b879ef55adbc897\" == md5(body))"
|
|
- type: dsl
|
|
name: hitachi
|
|
dsl:
|
|
- "len(body)==894 && status_code==200 && (\"41e9c43dc5e994ca7a40f4f92b50d01d\" == md5(body))"
|
|
- type: dsl
|
|
name: fortinet
|
|
dsl:
|
|
- "len(body)==318 && status_code==200 && (\"e462005902f81094ab3de44e4381de19\" == md5(body))"
|
|
- type: dsl
|
|
name: meinberg
|
|
dsl:
|
|
- "len(body)==1406 && status_code==200 && (\"4b2524b4f28eac7d0e872b0e1323c02d\" == md5(body))"
|