漏洞描述
Axis and Axis2 detection
id: axis-detect
info:
name: apache-axis-detect
author: dogasantos
severity: info
verified: true
description: Axis and Axis2 detection
rules:
r0:
request:
method: GET
path: /axis2/
expression: response.status == 200 && response.body.bcontains(b"Validate") && response.body.bcontains(b"Welcome") && response.body.bcontains(b"Axis") && response.body.bcontains(b"deployed") && response.body.bcontains(b"installation") && response.body.bcontains(b"Admin")
r1:
request:
method: GET
path: /axis/
expression: response.status == 200 && response.body.bcontains(b"Validate") && response.body.bcontains(b"Welcome") && response.body.bcontains(b"Axis") && response.body.bcontains(b"deployed") && response.body.bcontains(b"installation") && response.body.bcontains(b"Admin")
expression: r0() || r1()