0x727 / FingerprintHub

侦查守卫(ObserverWard)的指纹库
https://0x727.github.io/FingerprintHub/
MIT License
1.01k stars 188 forks source link

修改指纹-[phpmyadmin] #101

Closed j4vaovo closed 1 year ago

j4vaovo commented 1 year ago

测试目标

http://47.107.126.171/

指纹的Yaml规则

name: phpmyadmin
priority: 3
nuclei_tags:
  - - phpmyadmin
fingerprint:
  - path: /
    request_method: get
    request_headers: {}
    request_data: ''
    status_code: 0
    headers: {}
    keyword:
      - href="phpmyadmin.css.php
    favicon_hash: []
  - path: /
    request_method: get
    request_headers: {}
    request_data: ''
    status_code: 0
    headers:
      Set-Cookie: phpmyadmin=
    keyword: []
    favicon_hash: []
  - path: /
    request_method: get
    request_headers: {}
    request_data: ''
    status_code: 0
    headers:
      Set-Cookie: pma_lang=
    keyword: []
    favicon_hash: []
  - path: /
    request_method: get
    request_headers: {}
    request_data: ''
    status_code: 0
    headers: {}
    keyword:
      - pma_password
    favicon_hash: []
  - path: /phpmyadmin/index.php
    request_method: head
    request_headers: {}
    request_data: ''
    status_code: 0
    headers:
      Set-Cookie: phpmyadmin=
    keyword: []
    favicon_hash: []
  - path: /phpMyAdmin/index.php
    request_method: head
    request_headers: {}
    request_data: ''
    status_code: 0
    headers:
      Set-Cookie: phpmyadmin=
    keyword: []
    favicon_hash: []
  - path: /phpmyadmin/index.php
    request_method: head
    request_headers: {}
    request_data: ''
    status_code: 0
    headers:
      Set-Cookie: pma_lang=
    keyword: []
    favicon_hash: []
  - path: /phpMyAdmin/index.php
    request_method: head
    request_headers: {}
    request_data: ''
    status_code: 0
    headers:
      Set-Cookie: pma_lang=
    keyword: []
    favicon_hash: []
github-actions[bot] commented 1 year ago

验证过程:

点击展开查看

```bash URL: http://47.107.126.171/ HEADERS: server: nginx date: Mon, 08 May 2023 04:33:46 GMT content-type: text/html last-modified: Fri, 31 Dec 2021 11:13:34 GMT transfer-encoding: chunked connection: keep-alive vary: Accept-Encoding etag: W/"61cee5de-4601" STATUS_CODE: 200 TEXT: 欢迎您使用oneinstack

congratulations, oneinstack installed successfully!

oneinstack linux+nginx/tengine+mysql/mariadb/percona
+php+pureftpd+phpmyadmin+redis+memcached+jemalloc.

主机工具

探针 phpinfo phpmyadmin opcache

基本使用步骤

域名解析

域名控制

  • 阿里云(万网)
  • dnspod
  • cloudflare
详细教程

新建虚拟主机

建立网站

  • 新建虚拟主机 ./vhost.sh
  • 删除虚拟主机 ./vhost.sh --del
  • 管理ftp账号 ./pureftpd_vhost.sh
详细教程

部署网站

上线运行

  • phpmyadmin
  • 管理ftp账号 ./pureftpd_vhost.sh
  • 备份 ./backup_setup.sh
详细教程

如何添加虚拟主机?

《交互安装》

如何删除虚拟主机?

《交互安装》

ftp客户端推荐

filezilla: 下载地址

如何管理ftp账号?

《交互安装》

数据库

如何备份?

《交互安装》

如何管理服务?

nginx/tengine/openresty:

mysql/mariadb/percona:

postgresql:

mongodb:

php:

apache:

tomcat:

pure-ftpd:

redis:

memcached:

如何更新版本?

如何卸载?

云主机安全组必须打开如下端口:
  • ssh: 22
  • http: 80
  • https: 443
  • ftp: 21, 20000~30000

paypal: lj2007331@gmail.com ; 支付宝:lj2007331@gmail.com , 手机客户端扫描二维码捐赠:
《捐赠》 《捐赠》 《捐赠》
《捐赠》

版权所有 苏州鲜享网络科技有限公司 苏icp备2020059815号

回顶部

URL: http://47.107.126.171/phpmyadmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:33:47 GMT content-type: text/html; charset=UTF-8 connection: keep-alive vary: Accept-Encoding STATUS_CODE: 404 TEXT: URL: http://47.107.126.171/phpMyAdmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:33:48 GMT content-type: text/html; charset=utf-8 connection: keep-alive set-cookie: pma_lang=en; expires=Wed, 07-Jun-2023 04:33:48 GMT; Max-Age=2592000; path=/phpMyAdmin/; samesite=Strict; HttpOnly x-ob_mode: 1 x-frame-options: DENY referrer-policy: no-referrer content-security-policy: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' ;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-content-security-policy: default-src 'self' ;options inline-script eval-script;referrer no-referrer;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-webkit-csp: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval';referrer no-referrer;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-xss-protection: 1; mode=block x-content-type-options: nosniff x-permitted-cross-domain-policies: none x-robots-tag: noindex, nofollow expires: Mon, 08 May 2023 04:33:48 +0000 cache-control: no-store, no-cache, must-revalidate, pre-check=0, post-check=0, max-age=0 pragma: no-cache last-modified: Mon, 08 May 2023 04:33:48 +0000 vary: Accept-Encoding STATUS_CODE: 200 TEXT: ```

验证结果:

github-actions[bot] commented 1 year ago

验证过程:

点击展开查看

```bash URL: http://47.107.126.171/ HEADERS: server: nginx date: Mon, 08 May 2023 04:36:00 GMT content-type: text/html last-modified: Fri, 31 Dec 2021 11:13:34 GMT transfer-encoding: chunked connection: keep-alive vary: Accept-Encoding etag: W/"61cee5de-4601" STATUS_CODE: 200 TEXT: 欢迎您使用oneinstack

congratulations, oneinstack installed successfully!

oneinstack linux+nginx/tengine+mysql/mariadb/percona
+php+pureftpd+phpmyadmin+redis+memcached+jemalloc.

主机工具

探针 phpinfo phpmyadmin opcache

基本使用步骤

域名解析

域名控制

  • 阿里云(万网)
  • dnspod
  • cloudflare
详细教程

新建虚拟主机

建立网站

  • 新建虚拟主机 ./vhost.sh
  • 删除虚拟主机 ./vhost.sh --del
  • 管理ftp账号 ./pureftpd_vhost.sh
详细教程

部署网站

上线运行

  • phpmyadmin
  • 管理ftp账号 ./pureftpd_vhost.sh
  • 备份 ./backup_setup.sh
详细教程

如何添加虚拟主机?

《交互安装》

如何删除虚拟主机?

《交互安装》

ftp客户端推荐

filezilla: 下载地址

如何管理ftp账号?

《交互安装》

数据库

如何备份?

《交互安装》

如何管理服务?

nginx/tengine/openresty:

mysql/mariadb/percona:

postgresql:

mongodb:

php:

apache:

tomcat:

pure-ftpd:

redis:

memcached:

如何更新版本?

如何卸载?

云主机安全组必须打开如下端口:
  • ssh: 22
  • http: 80
  • https: 443
  • ftp: 21, 20000~30000

paypal: lj2007331@gmail.com ; 支付宝:lj2007331@gmail.com , 手机客户端扫描二维码捐赠:
《捐赠》 《捐赠》 《捐赠》
《捐赠》

版权所有 苏州鲜享网络科技有限公司 苏icp备2020059815号

回顶部

URL: http://47.107.126.171/phpmyadmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:36:01 GMT content-type: text/html; charset=UTF-8 connection: keep-alive vary: Accept-Encoding STATUS_CODE: 404 TEXT: URL: http://47.107.126.171/phpMyAdmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:36:02 GMT content-type: text/html; charset=utf-8 connection: keep-alive set-cookie: pma_lang=en; expires=Wed, 07-Jun-2023 04:36:02 GMT; Max-Age=2592000; path=/phpMyAdmin/; samesite=Strict; HttpOnly x-ob_mode: 1 x-frame-options: DENY referrer-policy: no-referrer content-security-policy: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' ;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-content-security-policy: default-src 'self' ;options inline-script eval-script;referrer no-referrer;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-webkit-csp: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval';referrer no-referrer;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-xss-protection: 1; mode=block x-content-type-options: nosniff x-permitted-cross-domain-policies: none x-robots-tag: noindex, nofollow expires: Mon, 08 May 2023 04:36:02 +0000 cache-control: no-store, no-cache, must-revalidate, pre-check=0, post-check=0, max-age=0 pragma: no-cache last-modified: Mon, 08 May 2023 04:36:02 +0000 vary: Accept-Encoding STATUS_CODE: 200 TEXT: Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/phpmyadmin/index.php", request_method: "head", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 200, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/phpMyAdmin/index.php", request_method: "head", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 200, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } URL: http://47.107.126.171/phpmyadmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:36:01 GMT content-type: text/html; charset=UTF-8 connection: keep-alive vary: Accept-Encoding STATUS_CODE: 404 TEXT: URL: http://47.107.126.171/phpMyAdmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:36:02 GMT content-type: text/html; charset=utf-8 connection: keep-alive set-cookie: pma_lang=en; expires=Wed, 07-Jun-2023 04:36:02 GMT; Max-Age=2592000; path=/phpMyAdmin/; samesite=Strict; HttpOnly x-ob_mode: 1 x-frame-options: DENY referrer-policy: no-referrer content-security-policy: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' ;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-content-security-policy: default-src 'self' ;options inline-script eval-script;referrer no-referrer;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-webkit-csp: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval';referrer no-referrer;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-xss-protection: 1; mode=block x-content-type-options: nosniff x-permitted-cross-domain-policies: none x-robots-tag: noindex, nofollow expires: Mon, 08 May 2023 04:36:02 +0000 cache-control: no-store, no-cache, must-revalidate, pre-check=0, post-check=0, max-age=0 pragma: no-cache last-modified: Mon, 08 May 2023 04:36:02 +0000 vary: Accept-Encoding STATUS_CODE: 200 TEXT: Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/phpmyadmin/index.php", request_method: "head", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 200, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/phpMyAdmin/index.php", request_method: "head", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 200, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } ```

验证结果:

github-actions[bot] commented 1 year ago

验证过程:

点击展开查看

```bash URL: http://47.107.126.171/ HEADERS: server: nginx date: Mon, 08 May 2023 04:41:45 GMT content-type: text/html last-modified: Fri, 31 Dec 2021 11:13:34 GMT transfer-encoding: chunked connection: keep-alive vary: Accept-Encoding etag: W/"61cee5de-4601" STATUS_CODE: 200 TEXT: 欢迎您使用oneinstack

congratulations, oneinstack installed successfully!

oneinstack linux+nginx/tengine+mysql/mariadb/percona
+php+pureftpd+phpmyadmin+redis+memcached+jemalloc.

主机工具

探针 phpinfo phpmyadmin opcache

基本使用步骤

域名解析

域名控制

  • 阿里云(万网)
  • dnspod
  • cloudflare
详细教程

新建虚拟主机

建立网站

  • 新建虚拟主机 ./vhost.sh
  • 删除虚拟主机 ./vhost.sh --del
  • 管理ftp账号 ./pureftpd_vhost.sh
详细教程

部署网站

上线运行

  • phpmyadmin
  • 管理ftp账号 ./pureftpd_vhost.sh
  • 备份 ./backup_setup.sh
详细教程

如何添加虚拟主机?

《交互安装》

如何删除虚拟主机?

《交互安装》

ftp客户端推荐

filezilla: 下载地址

如何管理ftp账号?

《交互安装》

数据库

如何备份?

《交互安装》

如何管理服务?

nginx/tengine/openresty:

mysql/mariadb/percona:

postgresql:

mongodb:

php:

apache:

tomcat:

pure-ftpd:

redis:

memcached:

如何更新版本?

如何卸载?

云主机安全组必须打开如下端口:
  • ssh: 22
  • http: 80
  • https: 443
  • ftp: 21, 20000~30000

paypal: lj2007331@gmail.com ; 支付宝:lj2007331@gmail.com , 手机客户端扫描二维码捐赠:
《捐赠》 《捐赠》 《捐赠》
《捐赠》

版权所有 苏州鲜享网络科技有限公司 苏icp备2020059815号

回顶部

URL: http://47.107.126.171/phpmyadmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:41:46 GMT content-type: text/html; charset=UTF-8 connection: keep-alive vary: Accept-Encoding STATUS_CODE: 404 TEXT: URL: http://47.107.126.171/phpMyAdmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:41:47 GMT content-type: text/html; charset=utf-8 connection: keep-alive set-cookie: pma_lang=en; expires=Wed, 07-Jun-2023 04:41:47 GMT; Max-Age=2592000; path=/phpMyAdmin/; samesite=Strict; HttpOnly x-ob_mode: 1 x-frame-options: DENY referrer-policy: no-referrer content-security-policy: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' ;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-content-security-policy: default-src 'self' ;options inline-script eval-script;referrer no-referrer;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-webkit-csp: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval';referrer no-referrer;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-xss-protection: 1; mode=block x-content-type-options: nosniff x-permitted-cross-domain-policies: none x-robots-tag: noindex, nofollow expires: Mon, 08 May 2023 04:41:47 +0000 cache-control: no-store, no-cache, must-revalidate, pre-check=0, post-check=0, max-age=0 pragma: no-cache last-modified: Mon, 08 May 2023 04:41:47 +0000 vary: Accept-Encoding STATUS_CODE: 200 TEXT: Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/phpmyadmin/index.php", request_method: "head", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/phpMyAdmin/index.php", request_method: "head", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/", request_method: "get", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } URL: http://47.107.126.171/phpmyadmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:41:46 GMT content-type: text/html; charset=UTF-8 connection: keep-alive vary: Accept-Encoding STATUS_CODE: 404 TEXT: URL: http://47.107.126.171/phpMyAdmin/index.php HEADERS: server: nginx date: Mon, 08 May 2023 04:41:47 GMT content-type: text/html; charset=utf-8 connection: keep-alive set-cookie: pma_lang=en; expires=Wed, 07-Jun-2023 04:41:47 GMT; Max-Age=2592000; path=/phpMyAdmin/; samesite=Strict; HttpOnly x-ob_mode: 1 x-frame-options: DENY referrer-policy: no-referrer content-security-policy: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' ;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-content-security-policy: default-src 'self' ;options inline-script eval-script;referrer no-referrer;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-webkit-csp: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval';referrer no-referrer;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none'; x-xss-protection: 1; mode=block x-content-type-options: nosniff x-permitted-cross-domain-policies: none x-robots-tag: noindex, nofollow expires: Mon, 08 May 2023 04:41:47 +0000 cache-control: no-store, no-cache, must-revalidate, pre-check=0, post-check=0, max-age=0 pragma: no-cache last-modified: Mon, 08 May 2023 04:41:47 +0000 vary: Accept-Encoding STATUS_CODE: 200 TEXT: Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/phpmyadmin/index.php", request_method: "head", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/phpMyAdmin/index.php", request_method: "head", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } Matching fingerprintV3WebFingerPrint { name: "phpmyadmin", priority: 3, request: WebFingerPrintRequest { path: "/", request_method: "get", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "Set-Cookie": "pma_lang=", }, keyword: [], }, } ```

验证结果:

github-actions[bot] commented 1 year ago

审核通过: