id: wp-debug-log info: name: WordPress Debug Log - Exposure author: geraldino2,dwisiswant0,philippedelteil severity: low description: Exposed Wordpress debug log. metadata: max-request: 4 tags: wp,wordpress,log,exposure http: - method: GET path: - "{{BaseURL}}/{{paths}}/debug.log" payloads: paths: - 'wp-content' - 'wordpress' - 'wp' - 'blog' stop-at-first-match: true host-redirects: true max-redirects: 3 max-size: 5000 matchers-condition: and matchers: - type: word part: header words: - octet-stream - text/plain condition: or - type: regex part: body regex: - "[[0-9]{2}-[a-zA-Z]{3}-[0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2} [A-Z]{3}] PHP" - type: status status: - 200 extractors: - type: dsl dsl: - to_string(content_length)+ " bytes" # digest: 490a00463044022040efbeedc82d9d94480ea18ce5f1e102cda95fa01dc99e5aedb1d939447c22e702203605546a92c3dd4a5f3f431b90a29661f6546a20a77e81874238de7dc2a0b01d:922c64590222798bb761d5b6d8e72950