0x727 / FingerprintHub

侦查守卫(ObserverWard)的指纹库
https://0x727.github.io/FingerprintHub/
MIT License
1.01k stars 188 forks source link

提交指纹-[appwrite] #65

Closed j4vaovo closed 1 year ago

j4vaovo commented 1 year ago

测试目标

https://kolorowanki.art:1443/

指纹的Yaml规则

name: appwrite
priority: 3
nuclei_tags:
  - - appwrite
fingerprint:
  - path: /
    request_method: get
    request_headers: {}
    request_data: ''
    status_code: 0
    headers: {}
    keyword:
      - <title>Sign In - Appwrite</title>
    favicon_hash: []
github-actions[bot] commented 1 year ago

验证过程:

点击展开查看

```bash URL: https://kolorowanki.art:1443/ HEADERS: access-control-allow-credentials: true access-control-allow-headers: Origin, Cookie, Set-Cookie, X-Requested-With, Content-Type, Access-Control-Allow-Origin, Access-Control-Request-Headers, Accept, X-Appwrite-Project, X-Appwrite-Key, X-Appwrite-Locale, X-Appwrite-Mode, X-Appwrite-JWT, X-Appwrite-Response-Format, X-SDK-Version, X-SDK-Name, X-SDK-Language, X-SDK-Platform, X-Appwrite-ID, Content-Range, Range, Cache-Control, Expires, Pragma access-control-allow-methods: GET, POST, PUT, PATCH, DELETE access-control-allow-origin: https://localhost access-control-expose-headers: X-Fallback-Cookies cache-control: no-store, no-cache, must-revalidate, max-age=0 content-length: 0 content-type: text/html date: Thu, 13 Apr 2023 08:47:29 GMT expires: 0 location: /auth/signin pragma: no-cache server: Appwrite x-content-type-options: nosniff x-debug-fallback: true x-debug-speed: 0.0025479793548584 x-frame-options: SAMEORIGIN x-ua-compatible: IE=Edge x-xss-protection: 1; mode=block; report=/v1/xss?url=%2F STATUS_CODE: 301 TEXT: NEXT_URL: https://kolorowanki.art:1443/auth/signin URL: https://kolorowanki.art:1443/auth/signin HEADERS: access-control-allow-credentials: true access-control-allow-headers: Origin, Cookie, Set-Cookie, X-Requested-With, Content-Type, Access-Control-Allow-Origin, Access-Control-Request-Headers, Accept, X-Appwrite-Project, X-Appwrite-Key, X-Appwrite-Locale, X-Appwrite-Mode, X-Appwrite-JWT, X-Appwrite-Response-Format, X-SDK-Version, X-SDK-Name, X-SDK-Language, X-SDK-Platform, X-Appwrite-ID, Content-Range, Range, Cache-Control, Expires, Pragma access-control-allow-methods: GET, POST, PUT, PATCH, DELETE access-control-allow-origin: https://localhost access-control-expose-headers: X-Fallback-Cookies cache-control: public, max-age=3888000 x-xss-protection: 1; mode=block; report=/v1/xss?url=%2Fauth%2Fsignin x-ua-compatible: IE=Edge content-type: text/html; charset=UTF-8 date: Thu, 13 Apr 2023 08:47:30 GMT expires: Sun, 28 May 2023 08:47:30 GMT server: Appwrite x-content-type-options: nosniff x-debug-fallback: true x-debug-speed: 0.0014479160308838 x-frame-options: SAMEORIGIN STATUS_CODE: 200 TEXT: sign in - appwrite

sign in

login failed. please check your credentials.

login using email and password



version 1.0.3.501
FAVICON: { "https://kolorowanki.art:1443/images/favicon.png?v=501": "db248209ca6800b895891ed86c3eb1fa", } Matching fingerprintV3WebFingerPrint { name: "appwrite", priority: 3, request: WebFingerPrintRequest { path: "/", request_method: "get", request_headers: {}, request_data: "", }, match_rules: WebFingerPrintMatch { status_code: 0, favicon_hash: [], headers: {}, keyword: [ "Sign In - Appwrite", ], }, } ```

验证结果:

github-actions[bot] commented 1 year ago

审核通过: