id: gitlab-public-snippets info: name: GitLab public snippets author: pdteam severity: info reference: - https://gist.github.com/vysecurity/20311c29d879e0aba9dcffbe72a88b10 - https://twitter.com/intigriti/status/1375078783338876929 metadata: max-request: 2 shodan-query: http.title:"GitLab" tags: gitlab,exposure,misconfig http: - method: GET path: - "{{BaseURL}}/explore/snippets" - "{{BaseURL}}/-/snippets" matchers-condition: and matchers: - type: word words: - 'Snippets · Explore · GitLab' - type: status status: - 200 - type: word negative: true condition: or words: - "No snippets found" - "Nothing here." # digest: 4a0a0047304502200b7c4f1e6cfdabd6a7a3a3253dafc9f23f435a8bae8eb11263da69149b466d3a0221009b706555b87b581900550ede409ad6ace79ba94e6bfe838e55e0cd4c915fafd0:922c64590222798bb761d5b6d8e72950