nuclei-templates/http/exposed-panels/pulse-secure-panel.yaml

35 lines
990 B
YAML

id: pulse-secure-panel
info:
name: Pulse Secure VPN Login Panel - Detect
author: bsysop
severity: info
description: Pulse Secure VPN login panel was detected.
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cwe-id: CWE-200
metadata:
max-request: 3
tags: panel,pulse,vpn
http:
- method: GET
path:
- "{{BaseURL}}/dana-na/auth/url_default/welcome.cgi"
- "{{BaseURL}}/dana-na/auth/url_2/welcome.cgi"
- "{{BaseURL}}/dana-na/auth/url_3/welcome.cgi"
stop-at-first-match: true
matchers-condition: or
matchers:
- type: word
part: header
words:
- "/dana-na/auth/welcome.cgi"
- type: regex
part: body
regex:
- "(?i)/dana-na/css/ds(_[a-f0-9]{64})?.css"
# digest: 490a0046304402205dceb1c9731416f54af938233efc4271aa67b0e3d4170afb25baef044e99ece702202b82e6426445f6d9ad1e6eaf9bd256ce6a6ead73e90de0e5ed3a377e62a7b610:922c64590222798bb761d5b6d8e72950