漏洞描述
Checks for a valid gitea account.
id: gitea-login-check
info:
name: gitea.com Login Check
author: parthmalhotra,pdresearch
severity: critical
description: Checks for a valid gitea account.
reference:
- https://owasp.org/www-community/attacks/Credential_stuffing
metadata:
max-request: 1
tags: cloud,creds-stuffing,login-check,gitea,vuln
self-contained: true
http:
- raw:
- |
POST https://gitea.com/user/login HTTP/1.1
Host: gitea.com
Content-Type: application/x-www-form-urlencoded
user_name={{username}}&password={{password}}
extractors:
- type: dsl
dsl:
- username
- password
matchers-condition: and
matchers:
- type: word
part: header
words:
- 'Location: /'
- type: status
status:
- 303
# digest: 4a0a00473045022100a81bf6c726ec7924b245a9163fc205edf54d09ff7f6f0ab7fd5c8a1a238968470220220cd6cd6aef5b9499ff83b74a039b2f8b7d6f3bd057465c7f010759cd3b5e26:922c64590222798bb761d5b6d8e72950