漏洞描述
Redis Commander Default Login credentials were discovered.
id: redis-commander-default-login
info:
name: Redis Commander - Default Login
author: DhiyaneshDK
severity: high
description: |
Redis Commander Default Login credentials were discovered.
metadata:
verified: true
max-request: 1
shodan-query: title:"Redis Commander"
tags: default-login,redis
variables:
username: admin
password: admin
http:
- raw:
- |
POST /signin HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
username={{username}}&password={{password}}
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"bearerToken":'
- '"queryToken":'
- '"ok":true'
condition: and
- type: status
status:
- 200
# digest: 490a004630440220159a6f2bb94ba9d8757d4d4699db0cbc7229631e3c8b760ce4c7350745e117f7022011847dbca7091ebdb509da33b602d9166245eb59b1d1394d1742693ea370a7a9:922c64590222798bb761d5b6d8e72950