1. id: zip-backup-files
    2. info:
    3. name: Compressed Backup File - Detect
    4. author: toufik-airane,dwisiswant0,ffffffff0x,pwnhxl,mastercho
    5. severity: medium
    6. description: Multiple compressed backup files were detected.
    7. classification:
    8. cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    9. cvss-score: 5.3
    10. cwe-id: CWE-200
    11. metadata:
    12. max-request: 1440
    13. tags: exposure,backup
    14. http:
    15. - method: GET
    16. path:
    17. - "{{BaseURL}}/{{FILENAME}}.{{EXT}}"
    18. attack: clusterbomb
    19. payloads:
    20. FILENAME:
    21. - "{{FQDN}}" # www.example.com
    22. - "{{RDN}}" # example.com
    23. - "{{DN}}" # example
    24. - "{{SD}}" # www
    25. - "{{date_time('%Y')}}" # 2023
    26. - "ROOT" # tomcat
    27. - "www"
    28. - "release"
    29. - "bin"
    30. - "bak"
    31. - "web"
    32. EXT:
    33. - "tar"
    34. - "rar"
    35. - "tar.gz"
    36. - "zip"
    37. max-size: 500 # Size in bytes - Max Size to read from server response
    38. matchers-condition: and
    39. matchers:
    40. - type: binary
    41. binary:
    42. - "7573746172202000" # tar
    43. - "7573746172003030" # tar
    44. - "377ABCAF271C" # 7z
    45. - "1f8b" # gz tar.gz
    46. - "526172211A0700" # rar RAR archive version 1.50
    47. - "526172211A070100" # rar RAR archive version 5.0
    48. - "FD377A585A0000" # xz tar.xz
    49. - "4C5A4950" # lz
    50. - "504B0304" # zip
    51. condition: or
    52. part: body
    53. - type: regex
    54. regex:
    55. - "application/[-\\w.]+"
    56. part: header
    57. - type: status
    58. status:
    59. - 200
    60. # digest: 4a0a00473045022100d7a028dbd5f7ea1cf187e1871d5065d2cd4d6ef130b04b73088820d6072435f50220673ba2cf4b143fa0d6b4b9b18d0d6290d902f76df58c73c764f7a99ccc1c671f:922c64590222798bb761d5b6d8e72950