漏洞描述
Protractor configuration file was detected.
id: protractor-config
info:
name: Protractor Configuration Exposure
author: DhiyaneshDK
severity: low
description: |
Protractor configuration file was detected.
reference:
- https://www.protractortest.org/#/api-overview
metadata:
verified: true
max-request: 1
shodan-query: html:"protractor.conf.js"
tags: devops,exposure,protractor,config,vuln
http:
- method: GET
path:
- "{{BaseURL}}/protractor.conf.js"
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'exports.config'
- 'capabilities:'
condition: and
- type: word
part: header
words:
- "application/javascript"
- type: status
status:
- 200
# digest: 4a0a00473045022100a7c549436562b7cf1e8e9967cf932987139fe836dcce53c8985e24ce4eabd367022042d9796971bd0f2db349777b9261bd04fb0710c82262e1fc8c4237bf020b24ce:922c64590222798bb761d5b6d8e72950