Files
nuclei-templates/http/technologies/jsf-detect.yaml
2025-10-26 16:17:37 +00:00

40 lines
1.1 KiB
YAML

id: jsf-detect
info:
name: JavaServer Faces Detection
author: brenocss,Moritz Nentwig
severity: info
description: Searches for JavaServer Faces content on a URL.
metadata:
max-request: 1
tags: jsf,tech,primefaces,richfaces,discovery
http:
- method: GET
path:
- "{{BaseURL}}"
host-redirects: true
max-redirects: 3
matchers-condition: or
matchers:
- type: dsl
name: javafaces
dsl:
- "(contains(body, 'javax.faces.resource') || contains(body, 'javax.faces.ViewState'))"
- type: dsl
name: primefaces
dsl:
- "contains(body, 'primefaces')"
- "contains(body, 'javax.faces.resource') || contains(body, 'javax.faces.ViewState')"
condition: and
- type: dsl
name: richfaces
dsl:
- "contains(body, 'richfaces')"
- "contains(body, 'javax.faces.resource') || contains(body, 'javax.faces.ViewState')"
condition: and
# digest: 490a004630440220036ca5c7aaca1fcb03644a48ff785c05926d775685cd83584f1a0a51456f4954022064deefacbfea5befad677f09f02428f79456916fcbf4b373706a040bf6f521bd:922c64590222798bb761d5b6d8e72950