diff --git a/default-logins/gude/gude-default-login.yaml b/default-logins/gude/gude-default-login.yaml new file mode 100644 index 00000000000..aacf4581c95 --- /dev/null +++ b/default-logins/gude/gude-default-login.yaml @@ -0,0 +1,33 @@ +id: gude-default-login + +info: + name: GUDE - Default Login + author: Bretss + severity: high + description: GUDE 2301 and 2302 default administrator login credentials (admin:admin) were detected. + reference: + - https://media.distrelec.com/Web/Downloads/_m/an/Gude_2302-1_ger_man.pdf + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L + cvss-score: 8.3 + cwe-id: CWE-522 + metadata: + max-request: 1 + shodan-query: http.html:"Expert Net Control" + fofa-query: body="Expert Net Control" + tags: gude,default-login + +http: + - method: GET + path: + - "{{BaseURL}}/ov.html?" + + headers: + Authorization: "Basic YWRtaW46YWRtaW4=" + + matchers: + - type: dsl + dsl: + - 'contains(body, "Control Panel")' + - 'status_code == 200' + condition: and