docker-remote-api: Docker Remote API

日期: 2025-08-01 | 影响软件: docker-remote-api | POC: 已公开

漏洞描述

fofa: port="2375" && server="docker"

PoC代码[已公开]

id: docker-remote-api

info:
  name: Docker Remote API
  author: zan8in
  severity: critical
  description: |-
    fofa: port="2375" && server="docker"
  tags: docker,remote,enum
  created: 2023/05/16

rules:
  r0:
    request:
      method: GET
      path: /version
    expression: response.status == 200 && response.body.bcontains(b'KernelVersion') && response.body.bcontains(b'BuildTime') && response.content_type.contains("application/json")
  r1:
    request:
      method: GET
      path: /containers/json
    expression: response.status == 200 && response.content_type.contains("application/json")
expression: r0() && r1()