This file is indexed.

/usr/share/doc/w3af-console/examples/script-hmap.w3af is in w3af-console 1.1svn5547-1.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
# generate a hmap fingerprint file

plugins
discovery serverHeader,hmap
discovery config hmap
set genFpF True
back

output console, textFile
output config console
set verbose False
back
output config textFile
set verbose True
back

back

http-settings
set userAgent w3af!
back

target
set target http://moth/
back
start

assert 'apache' in kb.kb.getData('hmap','serverString').lower()

exit