From 02c037cd46239e86a9c58b4bfff13c2fcb84577a Mon Sep 17 00:00:00 2001 From: Taleb <76521427+rumble773@users.noreply.github.com> Date: Tue, 7 Nov 2023 20:54:35 +0300 Subject: [PATCH 1/2] Update yii-debugger.yaml Adding an Extra path to get all the cases. http://XXXXXX/debug/default --- http/exposures/configs/yii-debugger.yaml | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/http/exposures/configs/yii-debugger.yaml b/http/exposures/configs/yii-debugger.yaml index 176d833f75f..02f3f5ed166 100644 --- a/http/exposures/configs/yii-debugger.yaml +++ b/http/exposures/configs/yii-debugger.yaml @@ -2,13 +2,13 @@ id: yii-debugger info: name: View Yii Debugger Information - author: geeknik - severity: low + author: geeknik, rumble773 + severity: medium reference: - https://yii2-framework.readthedocs.io/en/stable/guide/tool-debugger/ + tags: yii,debug,exposure metadata: max-request: 5 - tags: yii,debug,exposure http: - method: GET @@ -18,11 +18,11 @@ http: - "{{BaseURL}}/frontend/web/debug/default/view" - "{{BaseURL}}/web/debug/default/view" - "{{BaseURL}}/sapi/debug/default/view" + - "{{BaseURL}}/debug/default" host-redirects: true max-redirects: 2 stop-at-first-match: true - matchers-condition: and matchers: - type: status @@ -39,5 +39,3 @@ http: - "Memory" - "DB" condition: and - -# digest: 490a004630440220309c7637b23dcc346dc671f1eeb6a86253b771e8170239ac68188b127fdf289402206444c6bd6e28f24dcb149e605653a8801d8d025ad1fab73034cff71bbb3ee1da:922c64590222798bb761d5b6d8e72950 From aa7dcaea47ad7001b315e98af2d88ac17f3b8cab Mon Sep 17 00:00:00 2001 From: Ritik Chaddha <44563978+ritikchaddha@users.noreply.github.com> Date: Wed, 8 Nov 2023 14:03:42 +0530 Subject: [PATCH 2/2] Update yii-debugger.yaml --- http/exposures/configs/yii-debugger.yaml | 18 ++++++++++-------- 1 file changed, 10 insertions(+), 8 deletions(-) diff --git a/http/exposures/configs/yii-debugger.yaml b/http/exposures/configs/yii-debugger.yaml index 02f3f5ed166..9f66148e42f 100644 --- a/http/exposures/configs/yii-debugger.yaml +++ b/http/exposures/configs/yii-debugger.yaml @@ -2,13 +2,15 @@ id: yii-debugger info: name: View Yii Debugger Information - author: geeknik, rumble773 - severity: medium + author: geeknik,rumble773 + severity: low reference: - https://yii2-framework.readthedocs.io/en/stable/guide/tool-debugger/ - tags: yii,debug,exposure metadata: - max-request: 5 + max-request: 6 + verified: true + shodan-query: title:"Yii Debugger" + tags: yii,debug,exposure http: - method: GET @@ -25,10 +27,6 @@ http: stop-at-first-match: true matchers-condition: and matchers: - - type: status - status: - - 200 - - type: word words: - "