漏洞描述
app="ThinkPHP"
id: thinkphp-debug-detected
info:
name: Thinkphp Debug Detected
author: zan8in
severity: info
verified: true
description: app="ThinkPHP"
rules:
r0:
request:
method: GET
path: /
follow_redirects: true
expression: response.body.bcontains(b'>错误</span>') && response.body.bcontains(b'>SQL</span>') && response.body.bcontains(b'>调试</span>')
r1:
request:
method: GET
path: /?s=afrogThinkphpDebugTest
follow_redirects: true
expression: response.status == 404 && response.body.bcontains(b'HttpException') && response.body.bcontains(b'<td>THINK_PATH</td>') && response.body.bcontains(b'模块不存在:') && response.body.bcontains(b'afrogThinkphpDebugTest')
expression: r0() || r1()