漏洞描述
Apache ZooKeeper was able to be accessed without any required authentication.
fofa: port="2181" && protocol="zookeeper"
id: zookeeper-unauth
info:
name: Apache ZooKeeper - Unauthenticated Access
author: pdteam
severity: high
verified: true
description: |
Apache ZooKeeper was able to be accessed without any required authentication.
fofa: port="2181" && protocol="zookeeper"
reference:
- https://zookeeper.apache.org/security.html
tags: network,zookeeper,unauth
set:
hostname: request.url.host
host: request.url.domain
rules:
r0:
request:
type: tcp
host: "{{hostname}}"
data: "envi\r\nquit\r\n"
expression: response.raw.bcontains(b'zookeeper.version') && response.raw.bcontains(b'Environment')
r1:
request:
type: tcp
host: "{{host}}:2181"
data: "envi\r\nquit\r\n"
expression: response.raw.bcontains(b'zookeeper.version') && response.raw.bcontains(b'Environment')
expression: r0() || r1()