-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: detect Kronos Workforce Central when strings are separated #11547
base: main
Are you sure you want to change the base?
Conversation
Thanks so much for your contribution @missing0x00 ! :) |
You're welcome, thank you for the great tools! Nuclei Templates are powerful yet intuitive, love it. Looking forward to learning and contributing more. |
@DhiyaneshGeek The suggested changes would miss many instances unfortunately. Kronos is now part of UKG, so sometimes the title will be "UKG Workforce Central" or "Hostname - Workforce Central". My intent was to match when both Kronos and Workforce Central were listed in the page, but not the other strings. See examples here: |
Hi @missing0x00 Thanks for letting us know, i have updated the template accordingly, let me know if these changes looks good |
I have not seen these in any Kronos/UKG WFC instance I have checked. They also should not be necessary if we have
This could simply be
|
Hi @missing0x00 Let me know if these changes looks good Thanks |
Template / PR Information
/wfc/logon
endpointTemplate Validation
I've validated this template locally?
Additional Details
HTML response snippet: