From 94cc83dbdaa166382000e7e7773f50e6c0c6ef9f Mon Sep 17 00:00:00 2001 From: toxydose Date: Wed, 10 Apr 2019 15:42:15 +0300 Subject: [PATCH 1/3] add endpoints without trailing slashes --- Discovery/Web-Content/Logins.fuzz.txt | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/Discovery/Web-Content/Logins.fuzz.txt b/Discovery/Web-Content/Logins.fuzz.txt index 0176702..60d9f63 100644 --- a/Discovery/Web-Content/Logins.fuzz.txt +++ b/Discovery/Web-Content/Logins.fuzz.txt @@ -7,7 +7,9 @@ /admin.pl /admin.py /admin.rb +/admin /admin/ +/administrator /administrator/ /administrator.asp /administrator.aspx @@ -19,9 +21,11 @@ /administrator.py /administrator.rb /admnistrator.php3 +/backend /backend/ /cgi-bin/sqwebmail?noframes=1 /confluence/login.vm +/cpanel /cpanel/ /default.asp /exchange/logon.asp @@ -29,6 +33,7 @@ /index.php?u= /invocactf.php /login/ +/login /login.asp /login.aspx /login.cfm @@ -50,9 +55,11 @@ /logon.pl /logon.py /logon.rb +/typo3 /typo3/ /utilities/TreeView.asp /webeditor.php +/wp-admin /wp-admin/ /wp-login.php /wp-signup.php From 6aa736a75a65586fa95977be6763815a6f21879b Mon Sep 17 00:00:00 2001 From: toxydose Date: Wed, 10 Apr 2019 15:47:27 +0300 Subject: [PATCH 2/3] ShoreTel Connect login page GHDB-ID:5172 --- Discovery/Web-Content/Logins.fuzz.txt | 1 + Discovery/Web-Content/quickhits.txt | 1 + 2 files changed, 2 insertions(+) diff --git a/Discovery/Web-Content/Logins.fuzz.txt b/Discovery/Web-Content/Logins.fuzz.txt index 60d9f63..6e82bf0 100644 --- a/Discovery/Web-Content/Logins.fuzz.txt +++ b/Discovery/Web-Content/Logins.fuzz.txt @@ -55,6 +55,7 @@ /logon.pl /logon.py /logon.rb +/signin.php?ret= /typo3 /typo3/ /utilities/TreeView.asp diff --git a/Discovery/Web-Content/quickhits.txt b/Discovery/Web-Content/quickhits.txt index af6ef34..17279cf 100644 --- a/Discovery/Web-Content/quickhits.txt +++ b/Discovery/Web-Content/quickhits.txt @@ -2004,6 +2004,7 @@ /shell/ /shellz.php /shop.sql +/signin.php?ret= /signup.action /simple-backdoor.php /site.rar From 3251b35d54c4c9801d1e4c2671c147df8215f823 Mon Sep 17 00:00:00 2001 From: toxydose Date: Wed, 10 Apr 2019 15:54:03 +0300 Subject: [PATCH 3/3] update login endpoints --- Discovery/Web-Content/Logins.fuzz.txt | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Discovery/Web-Content/Logins.fuzz.txt b/Discovery/Web-Content/Logins.fuzz.txt index 6e82bf0..6681546 100644 --- a/Discovery/Web-Content/Logins.fuzz.txt +++ b/Discovery/Web-Content/Logins.fuzz.txt @@ -8,6 +8,8 @@ /admin.py /admin.rb /admin +/admin-login +/admin-login/ /admin/ /administrator /administrator/ @@ -55,6 +57,8 @@ /logon.pl /logon.py /logon.rb +/signin +/signin/ /signin.php?ret= /typo3 /typo3/