Skip to content

Commit cc99bf1

Browse files
authored
Create tinlance-sportybet-api-exposure.yaml to http/secrets/
New detector for sportybet api. Tested with Nuclei v3.x. #newtemplate
1 parent ae35871 commit cc99bf1

File tree

1 file changed

+29
-0
lines changed

1 file changed

+29
-0
lines changed
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
id: tinlance-sportybet-api-exposure
2+
3+
info:
4+
name: SportyBet / BetKing Admin or API Token Leak - Tinlance Detection
5+
author: Lloydcoder
6+
severity: high
7+
description: Catches leaked internal tokens and admin endpoints for popular Nigerian betting platforms.
8+
tags: exposure,betting,sportybet,betking,nigeria,tinlance
9+
10+
http:
11+
- method: GET
12+
path:
13+
- "{{BaseURL}}"
14+
15+
matchers-condition: and
16+
matchers:
17+
- type: regex
18+
regex:
19+
- 'Bearer\\s+[A-Za-z0-9-_]{50,}\\.[A-Za-z0-9-_]{50,}\\.[A-Za-z0-9-_]{50,}'
20+
- 'token["\']?\\s*[:=]\\s*["\']?eyJ[A-Za-z0-9-_]{100,}'
21+
- type: word
22+
words:
23+
- "sportybet"
24+
- "betking"
25+
- "bet9ja"
26+
- "admin"
27+
- "api_token"
28+
condition: or
29+
case-insensitive: true

0 commit comments

Comments
 (0)