exposed-bitkeeper: BitKeeper Configuration - Detect

日期: 2025-08-01 | 影响软件: BitKeeper | POC: 已公开

漏洞描述

BitKeeper configuration was detected.

PoC代码[已公开]

id: exposed-bitkeeper

info:
  name: BitKeeper Configuration - Detect
  author: daffainfo
  severity: low
  description: BitKeeper configuration was detected.
  reference:
    - https://www.bitkeeper.org/man/config-etc.html
  metadata:
    max-request: 1
  tags: config,exposure,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/BitKeeper/etc/config"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "BitKeeper configuration"
          - "logging"
          - "email"
          - "description"
        condition: and

      - type: status
        status:
          - 200
# digest: 490a00463044022001365e1d96bfdcf4f3344237475505cbb2485ef50ce404dd3ef9745e3fe6b7e302206730b898aaeb97fa53247961c1318fc3a0bf919442c3cfe8f9664f079f4e8aa9:922c64590222798bb761d5b6d8e72950