id: phpinfo
info:
name: info 信息泄露
author: 不动明王
severity: info
description: |
介绍:phpinfo是一个服务器的运行指令,可以显示php服务器的配置信息。
phpinfo() 同时是个很有价值的、包含所有 EGPCS(Environment, GET, POST, Cookie, Server) 数据的调试工具
一般不同容器都会默认开启这个功能
这里可以随意写你想写的介绍
reference:
- http://wiki.peiqi.tech/wiki/
- http://wiki.peiqi.tech/wiki/2
set:
randomfilename: randomLowercase(16)
rules:
mingzi1:
request:
method: GET
path: /phpinfo.php
expression: response.status == 200 && response.body.bcontains(b'<title>PHP') && response.body.bcontains(b'phpinfo()</title>')
mingzi2:
request:
method: GET
path: /phpinfo.php
expression: response.status == 200 && response.body.bcontains(b'<title>PHP') && response.body.bcontains(b'phpinfo()</title>')
mingzi3:
request:
method: POST
path: /{{randomfilename}}.php
body: username=admin&password=123456
expression: response.status == 200 && response.body.bcontains(b'<title>PHP') && response.body.bcontains(b'phpinfo()</title>')
expression: mingzi1() ||mingzi2() || mingzi3()