0x727 / FingerprintHub

侦查守卫(ObserverWard)的指纹库
https://0x727.github.io/FingerprintHub/
MIT License
1.01k stars 187 forks source link

提交指纹-[f5-big-ip] #15

Closed lsadaharu closed 2 years ago

lsadaharu commented 2 years ago

测试目标

https://ddsd.95590.cn

指纹的Yaml规则

name: f5-big-ip
priority: 3
nuclei_tags:
  - - bigip
fingerprint:
  - path: /
    request_method: get
    request_headers: {}
    request_data: ''
    status_code: 0
    headers: {}
    keyword:
      - content="F5 Networks, Inc."
    favicon_hash: []
  - path: /
    request_method: get
    request_headers: {}
    request_data: ''
    status_code: 0
    headers: {"set-cookie":"BIGipServerpool"}
    keyword: []
    favicon_hash: []
github-actions[bot] commented 2 years ago

验证过程:

点击展开查看

```bash Url: https://ddsd.95590.cn/ Headers: date: Fri, 17 Jun 2022 06:48:08 GMT content-type: text/html content-length: 154 connection: keep-alive location: https://www.ddsd-ccic.com set-cookie: TS0196d90a=01ccbc8f88b267b5bed57829bf1c8b138cbd58f0f4d1cf1d0d35ececef13d60127cc3cac4c84a7a4c0a40a75ba869de1e0b2209d6e; Path=/ BIGipServerpool_8044_171_95590_cn=1286275338.27679.0000; path=/ StatusCode: 302 Text: 302 found

302 found


nginx
NextUrl: https://www.ddsd-ccic.com/ Url: https://www.ddsd-ccic.com/ Headers: date: Fri, 17 Jun 2022 06:48:11 GMT content-type: text/html;charset=UTF-8 connection: keep-alive vary: Accept-Encoding x-frame-options: SAMEORIGIN SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block etag: W/"57208-1650617594000" last-modified: Fri, 22 Apr 2022 08:53:14 GMT set-cookie: BIGipServerpool_27263_dadishimao=1219494154.32618.0000; path=/; Httponly BIGipServerpool_171_8080=1806369034.36895.0000; path=/; Httponly TS0196d90a=01ccbc8f88702aef36dbf013598ef9d7c537ec0b798dabfc164e1dc1d80a3e7cbdba8a2c6efe02cfcf727d0e141e3fdc43012f04d5; Path=/ cciclb=!YeXLlNWjxmNN1z93N/fJnGyddclut5LkZ9HRWByIJPUZNRE/MHiuZk/KJpG+RNi6gz5FpGY0LcSv0kI=; path=/ transfer-encoding: chunked StatusCode: 200 Text: 大地时贷险官网-中国大地保险无抵押贷款保证保险-个人信用贷款增信

中国大地保险个人贷款保证保险品牌

公司新闻
机构热点
  • 贷款在线申请
  • 您的认真填写对贷款的通过率有重要影响。
```

验证结果:

github-actions[bot] commented 2 years ago

等待管理员审核:

github-actions[bot] commented 2 years ago

验证过程:

点击展开查看

```bash Url: https://ddsd.95590.cn/ Headers: date: Fri, 17 Jun 2022 06:51:27 GMT content-type: text/html content-length: 154 connection: keep-alive location: https://www.ddsd-ccic.com set-cookie: TS0196d90a=01ccbc8f882f3e409990a83a8bec04760244036014cb5ff380a6d954a4091ec27a637e3336401b29ffa6a013083b9e342d220a72d2; Path=/ BIGipServerpool_8044_171_95590_cn=1286275338.27679.0000; path=/ StatusCode: 302 Text: 302 found

302 found


nginx
NextUrl: https://www.ddsd-ccic.com/ Url: https://www.ddsd-ccic.com/ Headers: date: Fri, 17 Jun 2022 06:51:30 GMT content-type: text/html;charset=UTF-8 connection: keep-alive vary: Accept-Encoding x-frame-options: SAMEORIGIN SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block etag: W/"57208-1650617594000" last-modified: Fri, 22 Apr 2022 08:53:14 GMT set-cookie: BIGipServerpool_27263_dadishimao=1219494154.32618.0000; path=/; Httponly BIGipServerpool_171_8080=1789591818.36895.0000; path=/; Httponly TS0196d90a=01ccbc8f885bd6b526eaeef236cc9558f28bbfb6c3a4dd7d811b587eeb964dcf6ea88fda43da46b3e1baaa120b2f5799998c300367; Path=/ cciclb=!it+GSdIdApAjw493N/fJnGyddclut+6VYG/4K4M3Y/6uIJwrRv2pDm4XLGMaoyYWLQymkc6MMvQjuOg=; path=/ transfer-encoding: chunked StatusCode: 200 Text: 大地时贷险官网-中国大地保险无抵押贷款保证保险-个人信用贷款增信

中国大地保险个人贷款保证保险品牌

公司新闻
机构热点
  • 贷款在线申请
  • 您的认真填写对贷款的通过率有重要影响。
```

验证结果:

github-actions[bot] commented 2 years ago

等待管理员审核:

cn-kali-team commented 2 years ago

稍等,我改一下就可以了,你是不是想提交请求头的cookie的关键词

lsadaharu commented 2 years ago

我是想匹配返回包中setcookie中的关键字,如 BIGipServerpool等等

github-actions[bot] commented 2 years ago

验证过程:

点击展开查看

```bash Url: https://ddsd.95590.cn/ Headers: date: Fri, 17 Jun 2022 06:56:19 GMT content-type: text/html content-length: 154 connection: keep-alive location: https://www.ddsd-ccic.com set-cookie: TS0196d90a=01ccbc8f8862cc959ff92f06193b50f009ec8ae3979f8766bebdf4a35e491c7113b7ed6cf748fb99a3cdfb8ecf37f8d145a4294ee5; Path=/ BIGipServerpool_8044_171_95590_cn=1303052554.27679.0000; path=/ StatusCode: 302 Text: 302 found

302 found


nginx
NextUrl: https://www.ddsd-ccic.com/ Matching fingerprintV3WebFingerPrint { name: "f5-big-ip", priority: 3, request: WebFingerPrintRequest { path: "/", request_method: "get", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "set-cookie": "BIGipServerpool", }, keyword: [], }, } Url: https://www.ddsd-ccic.com/ Headers: date: Fri, 17 Jun 2022 06:56:23 GMT content-type: text/html;charset=UTF-8 connection: keep-alive vary: Accept-Encoding x-frame-options: SAMEORIGIN SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block etag: W/"57208-1650617594000" last-modified: Fri, 22 Apr 2022 08:53:14 GMT set-cookie: BIGipServerpool_27263_dadishimao=1202716938.32618.0000; path=/; Httponly BIGipServerpool_171_8080=1806369034.36895.0000; path=/; Httponly TS0196d90a=01ccbc8f881fd6efccc2c0f0dd8416e4df28f81170e37067185b8962f60bc1694aa70a902e5fce504b6b0b6d9e97bde3eb6bd2f1e4; Path=/ cciclb=!rxGNLHytw6YIpa13N/fJnGyddclut+gK8oLieyv4oaaa0mauajYnglnzWu3A2oIvFiGSLKNH+8BynVg=; path=/ transfer-encoding: chunked StatusCode: 200 Text: 大地时贷险官网-中国大地保险无抵押贷款保证保险-个人信用贷款增信

中国大地保险个人贷款保证保险品牌

公司新闻
机构热点
  • 贷款在线申请
  • 您的认真填写对贷款的通过率有重要影响。
Matching fingerprintV3WebFingerPrint { name: "f5-big-ip", priority: 3, request: WebFingerPrintRequest { path: "/", request_method: "get", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "set-cookie": "BIGipServerpool", }, keyword: [], }, } ```

验证结果:

github-actions[bot] commented 2 years ago

等待管理员审核:

github-actions[bot] commented 2 years ago

验证过程:

点击展开查看

```bash Url: https://ddsd.95590.cn/ Headers: date: Fri, 17 Jun 2022 06:56:30 GMT content-type: text/html content-length: 154 connection: keep-alive location: https://www.ddsd-ccic.com set-cookie: TS0196d90a=01ccbc8f887e40861c13e652231ebbcf41bc1ee03feb831902f7b7cbf0a08230a29c65f06a587a2937f36215190450cf3b88a5c67e; Path=/ BIGipServerpool_8044_171_95590_cn=1303052554.27679.0000; path=/ StatusCode: 302 Text: 302 found

302 found


nginx
NextUrl: https://www.ddsd-ccic.com/ Matching fingerprintV3WebFingerPrint { name: "f5-big-ip", priority: 3, request: WebFingerPrintRequest { path: "/", request_method: "get", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "set-cookie": "BIGipServerpool", }, keyword: [], }, } Url: https://www.ddsd-ccic.com/ Headers: date: Fri, 17 Jun 2022 06:56:34 GMT content-type: text/html;charset=UTF-8 connection: keep-alive vary: Accept-Encoding x-frame-options: SAMEORIGIN SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block etag: W/"57208-1650617594000" last-modified: Fri, 22 Apr 2022 08:53:14 GMT set-cookie: BIGipServerpool_27263_dadishimao=1219494154.32618.0000; path=/; Httponly BIGipServerpool_171_8080=1907032330.36895.0000; path=/; Httponly TS0196d90a=01ccbc8f8836ac5c65b071de42953fac108817bbd8a36ff32d31bb27c5a3f545765f497520012899a1f0e78c60c6ae9acd13682c1b; Path=/ cciclb=!zJK3fGu0//CZoaV3N/fJnGyddclut9kk8344mpshZKSX20h7kGF+l2H8KtdctNlxXrogF6p3O1o+D9k=; path=/ transfer-encoding: chunked StatusCode: 200 Text: 大地时贷险官网-中国大地保险无抵押贷款保证保险-个人信用贷款增信

中国大地保险个人贷款保证保险品牌

公司新闻
机构热点
  • 贷款在线申请
  • 您的认真填写对贷款的通过率有重要影响。
Matching fingerprintV3WebFingerPrint { name: "f5-big-ip", priority: 3, request: WebFingerPrintRequest { path: "/", request_method: "get", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: { "set-cookie": "BIGipServerpool", }, keyword: [], }, } ```

验证结果:

github-actions[bot] commented 2 years ago

等待管理员审核:

github-actions[bot] commented 2 years ago

审核通过:

cn-kali-team commented 2 years ago

我是想匹配返回包中setcookie中的关键字,如 BIGipServerpool等等

headers可以理解是一个字典,key是请求头的键,会先提取“set-cookie”的值,判断里面有没有“BIGipServerpool”这个关键词

lsadaharu commented 2 years ago

好的,谢谢师傅指点