漏洞描述
app="RabbitMQ-Management"
id: rabbitmq-default-password
info:
name: RabbitMQ Default Password
author: mumu0215
severity: high
verified: true
description: |-
app="RabbitMQ-Management"
tags: rabbitmq,defaultpassword
created: 2023/10/30
rules:
r0:
request:
method: GET
path: /api/whoami
expression: response.status == 401
r1:
request:
method: GET
path: /api/whoami
headers:
Authorization: Basic Z3Vlc3Q6Z3Vlc3Q=
expression: response.status == 200 && response.body.bcontains(b"\"name\":\"guest\"")
expression: r0() && r1()