漏洞描述
Searches for exposed Cobbler Directories
id: cobbler-exposed-directory
info:
name: Exposed Cobbler Directories
author: c-sh0
severity: medium
verified: false
description: Searches for exposed Cobbler Directories
rules:
r0:
request:
method: GET
path: /cobbler/
expression: response.status == 200 && response.body.bcontains(b'Index of /cobbler')
r1:
request:
method: GET
path: /cblr/
expression: response.status == 200 && response.body.bcontains(b'Index of /cblr')
expression: r0() && r1()