Description
Honeywell Scada configuration file was detected. The downloaded file opens with the file name and contains critical information about the destination address.
Honeywell Scada configuration file was detected. The downloaded file opens with the file name and contains critical information about the destination address.
id: honeywell-scada-config
info:
name: Honeywell Scada Configuration File - Detect
author: alperenkesk
severity: low
description: Honeywell Scada configuration file was detected. The downloaded file opens with the file name and contains critical information about the destination address.
reference:
- https://www.exploit-db.com/exploits/44734
metadata:
max-request: 1
tags: scada,config,exposure,edb,vuln
http:
- method: GET
path:
- "{{BaseURL}}/web_caps/webCapsConfig"
matchers-condition: and
matchers:
- type: word
words:
- "DeviceSubClass"
- "IPAddress"
condition: and
- type: status
status:
- 200
# digest: 4a0a0047304502210083088bb4485ad518203212f5a503a17db4787ed1fdaac26ea26b2a92615adfb502203d897eef87c6452148040e60b47f90cc1a27356ab175ff63ee0ba142866ca387:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.