# # Trial baloons to inspect the system # WEB_CLASS=Trialbaloons ############################### RULE=Double-Dash Pattern="GET //" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi RULE=BREAK-vendor Pattern="GET /vendor/" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi RULE=BREAK-webdav Pattern="GET /webdav/" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi RULE=BREAK-owa Pattern="GET /owa/" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi RULE=BREAK-junk-2 Pattern="GET /.env" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi # PHP myadmin stuff in any shade and color RULE=PMA-1 Pattern="GET /phpMyadmin" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi RULE=PMA-2 Pattern="GET /phpmyadmin" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi RULE=PMA-3 Pattern="GET /pma/" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi RULE=PMA-4 Pattern="GET /PMA/" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 4; return $?; fi RULE=Agent Pattern="GET /agent/" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 5; return $?; fi RULE=Agent2 Pattern="GET /agc/" #--------------- if [[ "$REPLY" =~ "$Pattern" ]]; then inject 5; return $?; fi