diff --git a/Discovery/Web-Content/README.md b/Discovery/Web-Content/README.md index 2e440a26..e2689a04 100644 --- a/Discovery/Web-Content/README.md +++ b/Discovery/Web-Content/README.md @@ -35,3 +35,14 @@ This list is a combination of the following wordlists: - raft-medium-directories.txt - raft-small-directories-lowercase.txt - raft-small-directories.txt + + +## WEB-INF-dict.txt +Use for: discovering sensitive j2ee files exploiting a lfi + +References: + +- https://gist.github.com/harisec/519dc6b45c6b594908c37d9ac19edbc3 +- https://github.com/projectdiscovery/nuclei-templates/blob/master/vulnerabilities/generic/generic-j2ee-lfi.yaml +- https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LFIModule.java + diff --git a/Discovery/Web-Content/WEB-INF-dict.txt b/Discovery/Web-Content/WEB-INF-dict.txt new file mode 100644 index 00000000..8a4667b0 --- /dev/null +++ b/Discovery/Web-Content/WEB-INF-dict.txt @@ -0,0 +1,170 @@ +JNLP-INF/APPLICATION.JNLP +META-INF/app-config.xml +META-INF/application-client.xml +META-INF/application.xml +META-INF/beans.xml +META-INF/CERT.SF +META-INF/container.xml +META-INF/context.xml +META-INF/eclipse.inf +META-INF/ejb-jar.xml +META-INF/ironjacamar.xml +META-INF/jboss-app.xml +META-INF/jboss-client.xml +META-INF/jboss-deployment-structure.xml +META-INF/jboss-ejb-client.xml +META-INF/jboss-ejb3.xml +META-INF/jboss-webservices.xml +META-INF/jbosscmp-jdbc.xml +META-INF/MANIFEST.MF +META-INF/openwebbeans/openwebbeans.properties +META-INF/persistence.xml +META-INF/ra.xml +META-INF/SOFTWARE.SF +META-INF/spring/application-context.xml +META-INF/weblogic-application.xml +META-INF/weblogic-ejb-jar.xml +WEB-INF/application-client.xml +WEB-INF/application_config.xml +WEB-INF/applicationContext.xml +WEB-INF/beans.xml +WEB-INF/cas-servlet.xml +WEB-INF/cas.properties +WEB-INF/classes/app-config.xml +WEB-INF/classes/application.properties +WEB-INF/classes/application.yml +WEB-INF/classes/applicationContext.xml +WEB-INF/classes/cas-theme-default.properties +WEB-INF/classes/commons-logging.properties +WEB-INF/classes/config.properties +WEB-INF/classes/countries.properties +WEB-INF/classes/db.properties +WEB-INF/classes/default-theme.properties +WEB-INF/classes/default_views.properties +WEB-INF/classes/demo.xml +WEB-INF/classes/faces-config.xml +WEB-INF/classes/fckeditor.properties +WEB-INF/classes/hibernate.cfg.xml +WEB-INF/classes/languages.xml +WEB-INF/classes/log4j.properties +WEB-INF/classes/log4j.xml +WEB-INF/classes/logback.xml +WEB-INF/classes/messages.properties +WEB-INF/classes/META-INF/app-config.xml +WEB-INF/classes/META-INF/persistence.xml +WEB-INF/classes/mobile.xml +WEB-INF/classes/persistence.xml +WEB-INF/classes/protocol_views.properties +WEB-INF/classes/resources/config.properties +WEB-INF/classes/services.properties +WEB-INF/classes/struts-default.vm +WEB-INF/classes/struts.properties +WEB-INF/classes/struts.xml +WEB-INF/classes/theme.properties +WEB-INF/classes/validation.properties +WEB-INF/classes/velocity.properties +WEB-INF/classes/web.xml +WEB-INF/components.xml +WEB-INF/conf/caches.dat +WEB-INF/conf/caches.properties +WEB-INF/conf/config.properties +WEB-INF/conf/core.xml +WEB-INF/conf/core_context.xml +WEB-INF/conf/daemons.properties +WEB-INF/conf/db.properties +WEB-INF/conf/editors.properties +WEB-INF/conf/jpa_context.xml +WEB-INF/conf/jtidy.properties +WEB-INF/conf/lutece.properties +WEB-INF/conf/mime.types +WEB-INF/conf/page_navigator.xml +WEB-INF/conf/search.properties +WEB-INF/conf/webmaster.properties +WEB-INF/conf/wml.properties +WEB-INF/config.xml +WEB-INF/config/dashboard-statistics.xml +WEB-INF/config/faces-config.xml +WEB-INF/config/metadata.xml +WEB-INF/config/mua-endpoints.xml +WEB-INF/config/security.xml +WEB-INF/config/soapConfig.xml +WEB-INF/config/users.xml +WEB-INF/config/web-core.xml +WEB-INF/config/webflow-config.xml +WEB-INF/config/webmvc-config.xml +WEB-INF/decorators.xml +WEB-INF/deployerConfigContext.xml +WEB-INF/dispatcher-servlet.xml +WEB-INF/ejb-jar.xml +WEB-INF/faces-config.xml +WEB-INF/geronimo-web.xml +WEB-INF/glassfish-resources.xml +WEB-INF/glassfish-web.xml +WEB-INF/hibernate.cfg.xml +WEB-INF/ias-web.xml +WEB-INF/ibm-web-bnd.xmi +WEB-INF/ibm-web-ext.xmi +WEB-INF/jax-ws-catalog.xml +WEB-INF/jboss-client.xml +WEB-INF/jboss-deployment-structure.xml +WEB-INF/jboss-ejb-client.xml +WEB-INF/jboss-ejb3.xml +WEB-INF/jboss-web.xml +WEB-INF/jboss-webservices.xml +WEB-INF/jetty-env.xml +WEB-INF/jetty-web.xml +WEB-INF/jonas-web.xml +WEB-INF/jrun-web.xml +WEB-INF/liferay-display.xml +WEB-INF/liferay-layout-templates.xml +WEB-INF/liferay-look-and-feel.xml +WEB-INF/liferay-plugin-package.xml +WEB-INF/liferay-portlet.xml +WEB-INF/local-jps.properties +WEB-INF/local.xml +WEB-INF/logback.xml +WEB-INF/logs/log.log +WEB-INF/openx-config.xml +WEB-INF/portlet-custom.xml +WEB-INF/portlet.xml +WEB-INF/quartz-properties.xml +WEB-INF/remoting-servlet.xml +WEB-INF/resin-web.xml +WEB-INF/resources/config.properties +WEB-INF/restlet-servlet.xml +WEB-INF/rexip-web.xml +WEB-INF/service.xsd +WEB-INF/sitemesh.xml +WEB-INF/spring-config.xml +WEB-INF/spring-config/application-context.xml +WEB-INF/spring-config/authorization-config.xml +WEB-INF/spring-config/management-config.xml +WEB-INF/spring-config/messaging-config.xml +WEB-INF/spring-config/presentation-config.xml +WEB-INF/spring-config/services-config.xml +WEB-INF/spring-config/services-remote-config.xml +WEB-INF/spring-configuration/filters.xml +WEB-INF/spring-context.xml +WEB-INF/spring-dispatcher-servlet.xml +WEB-INF/spring-mvc.xml +WEB-INF/spring-ws-servlet.xml +WEB-INF/spring/webmvc-config.xml +WEB-INF/springweb-servlet.xml +WEB-INF/struts-config-ext.xml +WEB-INF/struts-config-widgets.xml +WEB-INF/struts-config.xml +WEB-INF/sun-jaxws.xml +WEB-INF/sun-web.xml +WEB-INF/tiles-defs.xml +WEB-INF/tjc-web.xml +WEB-INF/trinidad-config.xml +WEB-INF/urlrewrite.xml +WEB-INF/validation.xml +WEB-INF/validator-rules.xml +WEB-INF/web-borland.xml +WEB-INF/web-jetty.xml +WEB-INF/web.xml +WEB-INF/web.xml.jsf +WEB-INF/web2.xml +WEB-INF/weblogic.xml +WEB-INF/workflow-properties.xml