From 61b92c599d2240a2dfd9214c72b2751e4ad35d09 Mon Sep 17 00:00:00 2001 From: Tonimir Kisasondi Date: Fri, 15 Mar 2019 22:26:08 +0100 Subject: [PATCH 1/2] Update spring-boot.txt Added some other paths according to: https://www.veracode.com/blog/research/exploiting-spring-boot-actuators --- Discovery/Web-Content/spring-boot.txt | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/Discovery/Web-Content/spring-boot.txt b/Discovery/Web-Content/spring-boot.txt index 6079233..7f39ea9 100644 --- a/Discovery/Web-Content/spring-boot.txt +++ b/Discovery/Web-Content/spring-boot.txt @@ -1,6 +1,7 @@ trace health loggers +logfile metrics autoconfig heapdump @@ -11,3 +12,8 @@ configprops mappings auditevents beans +/actuator/dump +/actuator/trace +/actuator/logfile +/actuator/mappings +/actuator/env From eaccabd89aaf83dff95ed585bbe940225cedc2c0 Mon Sep 17 00:00:00 2001 From: Tonimir Kisasondi Date: Fri, 15 Mar 2019 22:37:48 +0100 Subject: [PATCH 2/2] Update spring-boot.txt --- Discovery/Web-Content/spring-boot.txt | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/Discovery/Web-Content/spring-boot.txt b/Discovery/Web-Content/spring-boot.txt index 7f39ea9..d4a82f6 100644 --- a/Discovery/Web-Content/spring-boot.txt +++ b/Discovery/Web-Content/spring-boot.txt @@ -12,8 +12,10 @@ configprops mappings auditevents beans -/actuator/dump -/actuator/trace -/actuator/logfile -/actuator/mappings -/actuator/env +actuator/dump +actuator/trace +actuator/logfile +actuator/mappings +actuator/env +jolokia +list