Files
sif/modules/recon/zipkin-exposure.yaml
T
TigahandGitHub 16ffcc240b feat(modules): add loki, jaeger and zipkin exposure modules (#248)
add recon modules for unauthenticated observability backends that leak service topology and log data: loki serves its log query api when auth_enabled is false (401 otherwise), and jaeger and zipkin ship no authentication so a reachable instance exposes the service map and trace data.
2026-07-02 12:55:58 -07:00

38 lines
829 B
YAML

# Zipkin Tracing Server Exposure Detection Module
id: zipkin-exposure
info:
name: Zipkin Tracing Server Exposure
author: sif
severity: medium
description: Detects an exposed Zipkin server that leaks the internal service topology and trace data over its unauthenticated api
tags: [zipkin, tracing, distributed-tracing, observability, topology, exposure, unauth, recon]
type: http
http:
method: GET
paths:
- "{{BaseURL}}/zipkin/config.json"
matchers:
- type: word
part: body
words:
- "\"queryLimit\""
- "\"defaultLookback\""
- "\"searchEnabled\""
condition: and
- type: status
status:
- 200
extractors:
- type: regex
name: zipkin_environment
part: body
regex:
- '"environment"\s*:\s*"([^"]*)"'
group: 1