Added apache-streampipes-detect.yaml and CVE-2024-29868.yaml + moved … #10131
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Template / PR Information
apache-streampipes-detect.yaml
: I made a template to detect if an Apache StreamPipes instance is detected. It checks for the presence of "apache streampipes" in the body of two paths and then checks for the favicon hash (there are 2 because the one that shodan associates with Apache StreamPipes installations is different from the one manually calculated by me).CVE-2024-29868.yaml
: I created a template that detects for the presence of CVE-2024-29868 by looking if the version is included between the vulnerable ones and the configuration matches with the conditions to exploit the vulnerability.http/technologies/apache-allura-detect.yaml
tohttp/technologies/apache/apache-allura-detect.yaml
: In the process of forking the repo and adding my templates I noticed that the templateapache-allura-detect.yaml
was misplaced as it was not in the "apache" directory so I moved it there.Template Validation
I've validated this template locally?