helpjuice-takeover: helpjuice takeover detection

日期: 2025-08-01 | 影响软件: helpjuice | POC: 已公开

漏洞描述

helpjuice takeover was detected.

PoC代码[已公开]

id: helpjuice-takeover

info:
  name: helpjuice takeover detection
  author: pdteam
  severity: high
  description: helpjuice takeover was detected.
  reference:
    - https://github.com/EdOverflow/can-i-take-over-xyz
  metadata:
    max-request: 1
  tags: takeover,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    matchers-condition: and
    matchers:
      - type: dsl
        dsl:
          - Host != ip

      - type: word
        words:
          - We could not find what you're looking for.

    extractors:
      - type: dsl
        dsl:
          - cname
# digest: 490a00463044022029a46154e0317eb44db389983c69a686eaff1f09e5f990b6dc366eb4e492e27802205968903af19f7676519ee27b2d3b6e6c515725935e2f0eb7960de4a32840cd84:922c64590222798bb761d5b6d8e72950

相关漏洞推荐