漏洞描述
fofa: port="2375" && server="docker"
id: docker-remote-api
info:
name: Docker Remote API
author: zan8in
severity: critical
description: |
fofa: port="2375" && server="docker"
reference:
- http://wiki.peiqi.tech/redteam/vulnerability/unauthorized/Docker%202375%E7%AB%AF%E5%8F%A3.html
rules:
r0:
request:
method: GET
path: /version
expression: response.status == 200 && response.body.bcontains(b'KernelVersion') && response.body.bcontains(b'BuildTime') && response.content_type.contains("application/json")
r1:
request:
method: GET
path: /containers/json
expression: response.status == 200 && response.content_type.contains("application/json")
expression: r0() && r1()