Coder Social home page Coder Social logo

CVE-2021-44910 about afrog HOT 4 OPEN

leonardo-o1 avatar leonardo-o1 commented on June 2, 2024 1
CVE-2021-44910

from afrog.

Comments (4)

leonardo-o1 avatar leonardo-o1 commented on June 2, 2024 1

感谢,不过你的 expression 判断过于简单,容易误报,下次再增加一些唯一性验证会更好。

好的,添加了认证前访问401的判断,再看下呢

from afrog.

ViCrack avatar ViCrack commented on June 2, 2024 1

不用加认证前访问的判断吧,节省发包量,按照这个图来说,因为返回的json结构字段比较多,所以增加字段特征应该就足够了

      - '"success":true'
      - '"account":'
      - '"password":'
      - createDept
      - xxxxxxx
      - xxxxxxxx

图片

nuclei也有这个的yaml

from afrog.

zan8in avatar zan8in commented on June 2, 2024

感谢,不过你的 expression 判断过于简单,容易误报,下次再增加一些唯一性验证会更好。

from afrog.

zan8in avatar zan8in commented on June 2, 2024

不错的办法,这个漏洞之前写过,现已上传到github,你看下是否需要把你的poc 合并进去

from afrog.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.