ftpconfig: Atom remote-ssh ftpconfig Exposure

日期: 2025-08-01 | 影响软件: Atom remote-ssh | POC: 已公开

漏洞描述

Created by remote-ssh for Atom, contains SFTP/SSH server details and credentials

PoC代码[已公开]

id: ftpconfig

info:
  name: Atom remote-ssh ftpconfig Exposure
  author: geeknik,DhiyaneshDK
  severity: high
  description: Created by remote-ssh for Atom, contains SFTP/SSH server details and credentials
  metadata:
    verified: true
    max-request: 1
    shodan-query: html:ftpconfig
  tags: atom,ftp,config,exposure,files,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/.ftpconfig"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - '"protocol":'
          - '"host":'
          - '"user":'
          - '"passphrase":'
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a0047304502204f30cccbc75740e1aed43554350a5e4bcb63d86d1bd56a6429f5da0342f78992022100e630481645e40a51e2ec7c051e6f758f6641a8b3604a9c0c6f2660b8b33e77a9:922c64590222798bb761d5b6d8e72950