Skip to content

Commit ae35871

Browse files
authored
Create tinlance-remita-credentials-exposure.yaml to http/secrets/
New detector for Remita. Tested with Nuclei v3.x. #newtemplate
1 parent ebfd7b5 commit ae35871

File tree

1 file changed

+28
-0
lines changed

1 file changed

+28
-0
lines changed
Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
id: tinlance-remita-credentials-exposure
2+
3+
info:
4+
name: Remita Merchant ID & API Key Exposure - Tinlance Detection
5+
author: Lloydcoder
6+
severity: high
7+
description: Detects leaked Remita merchant IDs, API keys and secret hashes used across Nigerian billing systems.
8+
tags: exposure,remita,nigeria,fintech,tinlance,lloydcoder
9+
10+
http:
11+
- method: GET
12+
path:
13+
- "{{BaseURL}}"
14+
15+
matchers-condition: and
16+
matchers:
17+
- type: regex
18+
regex:
19+
- "\\b\\d{10,15}\\|[a-zA-Z0-9]{40,}\\b"
20+
- "merchantId[\"']?\\s*[:=]\\s*[\"']?\\d{10,}[\"']?"
21+
- type: word
22+
words:
23+
- "remita"
24+
- "merchantId"
25+
- "apiKey"
26+
- "publicKey"
27+
condition: or
28+
case-insensitive: true

0 commit comments

Comments
 (0)