Skip to content

Commit

Permalink
Update and rename redpanda-console-detection.yaml to http/misconfigur…
Browse files Browse the repository at this point in the history
…ation/redpanda-console.yaml
  • Loading branch information
DhiyaneshGeek authored Oct 21, 2024
1 parent d83860a commit e14fbf3
Show file tree
Hide file tree
Showing 2 changed files with 33 additions and 37 deletions.
33 changes: 33 additions & 0 deletions http/misconfiguration/redpanda-console.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
id: redpanda-console

info:
name: Redpanda Console - Exposure
author: kh4sh3i
severity: medium
description: |
Unauthorized access to the Redpanda Console could allow attackers to view or manipulate streaming data, monitor clusters, or access configuration information, leading to potential data leaks or service disruption.
impact: |
Exposing the Redpanda Console to the public can result in unauthorized access, leading to data leaks, misconfigurations, or even denial of service attacks on the streaming infrastructure.
reference:
- https://github.com/redpanda-data/console
metadata:
verified: true
max-request: 1
shodan-query: title:"Redpanda Console"
tags: misconfig,redpanda,console,streaming

http:
- method: GET
path:
- "{{BaseURL}}/overview"

matchers-condition: and
matchers:
- type: word
part: body
words:
- "Redpanda Console"

- type: status
status:
- 200
37 changes: 0 additions & 37 deletions redpanda-console-detection.yaml

This file was deleted.

0 comments on commit e14fbf3

Please sign in to comment.