michelin / ChopChop

ChopChop is a CLI to help developers scanning endpoints and identifying exposition of sensitive services/files/folders.
Other
674 stars 78 forks source link

Confusion: Azure VS Tomcat #4

Closed cnotin closed 4 years ago

cnotin commented 4 years ago

Regarding this: https://github.com/michelin/ChopChop/blob/8feacb57ff92b2ee9bbe3cac15a3aca6a1b770d5/chopchop.yml#L45-L50

I might be mistaken as I don't know what would be a "Azure installation by default", but usually "catalina" refers to Tomcat so there's maybe a confusion here :)

PaulSec commented 4 years ago

You are "partially" right. It's actually part of the default page when you spin it up through Azure and this is why we were referencing it like this in our infra :)

cnotin commented 4 years ago

But not everything on Azure is Tomcat I guess ;) As you prefer!

cnotin commented 4 years ago

And having "catalina.base" in the default page isn't Azure specific, as we can see: https://www.shodan.io/search?query=http.html%3A%22catalina.base%22 https://censys.io/ipv4?q=%22catalina.base%22

PaulSec commented 4 years ago

Yes you are right, I removed it from the signatures, good catch Clément :-)

cnotin commented 4 years ago

Cheers Paul!