mkrs2404 / tickets

0 stars 0 forks source link

External Service Interaction (external-service-interaction) found on honey.scanme.sh #46

Closed mkrs2404 closed 1 month ago

mkrs2404 commented 4 months ago

Details: external-service-interaction matched at honey.scanme.sh

Protocol: HTTP

Full URL: https://honey.scanme.sh

Timestamp: Tue Apr 30 19:28:13 +0530 IST 2024

Template Information

Key Value
Name External Service Interaction
Authors andreluna
Tags miscellaneous, http, misc, oast
Severity info
Description External Service interaction via Host Header Injection.
CWE-ID CWE-918,CWE-406
CVSS-Score 0.00

Request

GET / HTTP/1.1
Host: coofgv4mjeun8ktjo61gctas655f1i14x.oast.me
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/605.1.33 (KHTML, like Gecko) Version/9.1.2 Safari/605.1.33
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

Response

HTTP/1.1 200 OK
Connection: close
Content-Length: 275
Content-Type: text/html
Date: Tue, 30 Apr 2024 13:58:12 GMT

GET / HTTP/1.1
Host: coofgv4mjeun8ktjo61gctas655f1i14x.oast.me
Accept: */*
Accept-Encoding: gzip
Accept-Language: en
Connection: close
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/605.1.33 (KHTML, like Gecko) Version/9.1.2 Safari/605.1.33

Interaction Data

dns (A) Interaction from 172.253.10.3 at coofgv4mjeun8ktjo61gctas655f1i14x Interaction Request

;; opcode: QUERY, status: NOERROR, id: 26968
;; flags: cd; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;COoFgV4MjEun8ktjo61GcTaS655F1i14X.oASt.me. IN   A

Interaction Response

;; opcode: QUERY, status: NOERROR, id: 26968
;; flags: qr aa cd; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2

;; QUESTION SECTION:
;COoFgV4MjEun8ktjo61GcTaS655F1i14X.oASt.me. IN   A

;; ANSWER SECTION:
COoFgV4MjEun8ktjo61GcTaS655F1i14X.oASt.me.  3600    IN  A   178.128.209.14

;; AUTHORITY SECTION:
COoFgV4MjEun8ktjo61GcTaS655F1i14X.oASt.me.  3600    IN  NS  ns1.oast.me.
COoFgV4MjEun8ktjo61GcTaS655F1i14X.oASt.me.  3600    IN  NS  ns2.oast.me.

;; ADDITIONAL SECTION:
ns1.oast.me.    3600    IN  A   178.128.209.14
ns2.oast.me.    3600    IN  A   178.128.209.14

References:

CURL command

curl -X 'GET' -H 'Accept: */*' -H 'Accept-Language: en' -H 'Host: coofgv4mjeun8ktjo61gctas655f1i14x.oast.me' -H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/605.1.33 (KHTML, like Gecko) Version/9.1.2 Safari/605.1.33' 'https://honey.scanme.sh'

Generated by Nuclei v3.2.5