漏洞描述
Checks for a valid chef.io account.
id: chefio-login-check
info:
name: Chef.io Login Check
author: parthmalhotra,pdresearch
severity: critical
description: Checks for a valid chef.io account.
reference:
- https://owasp.org/www-community/attacks/Credential_stuffing
metadata:
max-request: 1
tags: cloud,creds-stuffing,login-check,chefio,vuln
self-contained: true
http:
- raw:
- |
POST https://api.chef.io/login HTTP/1.1
Host: api.chef.io
Content-Type: application/x-www-form-urlencoded
utf8=%E2%9C%93&authenticity_token=&authenticity_token=&to=https://api.chef.io/login-success&username={{username}}&password={{password}}&commit=Sign+In
matchers-condition: and
matchers:
- type: word
part: header
words:
- 'Location: https://api.chef.io/login-success'
- type: status
status:
- 302
# digest: 4a0a0047304502200f0a690d466722638b5eb47824235d6e2b41a485c17a4209b33fbe47399d5f91022100d84619cc762a9d687fbf45ce2a0f2473d6320cdacb39a5ee138c518c469fdf7e:922c64590222798bb761d5b6d8e72950