2021-11-21 14:26:39 +05:30
id : apache-filename-enum
2021-05-12 20:30:15 +00:00
info :
2021-11-21 14:26:39 +05:30
name : Apache Filename Enumeration
2021-05-12 20:30:15 +00:00
author : geeknik
2022-04-22 13:38:41 +03:00
severity : low
2021-05-12 20:30:15 +00:00
description : If the client provides an invalid Accept header, the server will respond with a 406 Not Acceptable error containing a pseudo directory listing.
2021-08-18 14:37:49 +03:00
reference :
2021-05-12 20:30:15 +00:00
- https://hackerone.com/reports/210238
- https://www.acunetix.com/vulnerabilities/web/apache-mod_negotiation-filename-bruteforcing/
2023-04-28 13:41:21 +05:30
metadata :
max-request : 1
2023-10-14 16:57:55 +05:30
tags : apache,misconfig,hackerone
2021-05-12 20:31:52 +00:00
2023-04-27 09:58:59 +05:30
http :
2021-05-12 20:30:15 +00:00
- method : GET
2023-10-14 16:57:55 +05:30
2021-05-12 20:30:15 +00:00
headers :
Accept : "fake/value"
path :
- "{{BaseURL}}/index"
2021-05-12 20:31:52 +00:00
2021-05-12 20:30:15 +00:00
matchers-condition : and
matchers :
- type : status
status :
- 406
2023-10-14 16:57:55 +05:30
2021-05-12 20:30:15 +00:00
- type : word
words :
- "Not Acceptable"
- "Available variants:"
- "<address>Apache Server at"
condition : and
2024-12-01 13:57:55 +00:00
# digest: 4a0a0047304502203e734793535f2b117756856e4c502b483402fc63495b28e73de3fb17fc6ed967022100dcaba327a5b921703e1a811c155db4369b3160282f1247f8d822fc3305211160:922c64590222798bb761d5b6d8e72950