漏洞描述
openvpn-monitor is a simple python program to generate html that displays the status of an OpenVPN server, including all current connections.
id: openvpn-monitor-disclosure
info:
name: OpenVPN Monitor Disclosure
author: geeknik
severity: medium
verified: true
description: openvpn-monitor is a simple python program to generate html that displays the status of an OpenVPN server, including all current connections.
reference:
- https://openvpn-monitor.openbytes.ie/
rules:
r0:
request:
method: GET
path: /openvpn-monitor/
expression: response.status==200 && response.body.bcontains(b'OpenVPN Status Monitor') && response.body.bcontains(b'Username') && response.body.bcontains(b'VPN IP') && response.body.bcontains(b'Remote IP')
expression: r0()