Vulinbox(敏感信息与敏感文件泄露)

一二直接访问即可

Swagger暴露会导致接口参数一览无余

swagger UI泄露

观察到页面为空,可以借助工具对目录进行扫码

bash 复制代码
dirsearch -u "http://192.168.17.1:8787/swagger/" -w test.txt

直接访问即可

git文件泄露

同样的借助dirsearch对git目录进行扫描

bash 复制代码
dirsearch -u "http://192.168.17.1:8787/git/website/"
result 复制代码
[17:28:25] 200 -  137B  - /git/website/.git/config
[17:28:25] 500 -  515B  - /git/website/.git/logs/refs/remotes/origin/HEAD
[17:28:25] 200 -  289B  - /git/website/.git/index
[17:28:25] 200 -  822B  - /git/website/.git/logs/HEAD
[17:28:25] 200 -    2KB - /git/website/.git/hooks/pre-commit.sample
[17:28:25] 200 -  478B  - /git/website/.git/hooks/applypatch-msg.sample
[17:28:25] 500 -  505B  - /git/website/.git/refs/remotes/origin/HEAD
[17:28:25] 500 -  457B  - /git/website/.git/
[17:28:25] 500 -  469B  - /git/website/.git/hooks/
[17:28:25] 200 -  189B  - /git/website/.git/hooks/post-update.sample
[17:28:25] 200 -    5KB - /git/website/.git/hooks/pre-rebase.sample
[17:28:25] 200 -  424B  - /git/website/.git/hooks/pre-applypatch.sample
[17:28:25] 200 -   41B  - /git/website/.git/refs/heads/master
[17:28:25] 200 -   73B  - /git/website/.git/description
[17:28:25] 200 -    1KB - /git/website/.git/hooks/pre-push.sample
[17:28:25] 200 -  300B  - /git/website/.git/logs/refs/heads/master
[17:28:25] 200 -   23B  - /git/website/.git/HEAD
[17:28:25] 200 -    1KB - /git/website/.git/hooks/prepare-commit-msg.sample
[17:28:25] 500 -  477B  - /git/website/.git/refs/stash
[17:28:25] 200 -  896B  - /git/website/.git/hooks/commit-msg.sample
[17:28:25] 200 -    4KB - /git/website/.git/hooks/update.sample
[17:28:25] 500 -  473B  - /git/website/.git/objects/
[17:28:25] 500 -  483B  - /git/website/.git/objects/info/
[17:28:25] 500 -  483B  - /git/website/.git/objects/pack/
[17:28:25] 500 -  467B  - /git/website/.git/info/
[17:28:25] 200 -  240B  - /git/website/.git/info/exclude
[17:28:25] 500 -  475B  - /git/website/.git/info/refs
[17:28:25] 500 -  475B  - /git/website/.git/ORIG_HEAD
[17:28:25] 200 -   12B  - /git/website/.git/COMMIT_EDITMSG
[17:28:25] 500 -  483B  - /git/website/.git/NOTES_EDITMSG
[17:28:25] 500 -  475B  - /git/website/.gitattributes
[17:28:25] 500 -  469B  - /git/website/.gitmodules
[17:28:25] 500 -  479B  - /git/website/.git-credentials
[17:28:25] 500 -  459B  - /git/website/.gitsh
[17:28:25] 500 -  457B  - /git/website/.svn/
[17:28:25] 500 -  455B  - /git/website/.hg/
[17:28:25] 500 -  457B  - /git/website/.gitk
[17:28:25] 500 -  467B  - /git/website/.gitignore

可以使用githack对git目录下载

相关推荐
盟接之桥5 小时前
什么是EDI(电子数据交换)|制造业场景解决方案
大数据·网络·安全·汽车·制造
科技云报道5 小时前
安全进入“AI自主攻击”时代,瑞数信息如何用AI对抗AI
人工智能·安全
KnowSafe7 小时前
证书自动化解决方案哪家更可靠?
运维·服务器·安全·https·自动化·ssl
KnowSafe7 小时前
2026年证书自动化解决方案选型指南
运维·安全·自动化·ssl·itrustssl
b55t4ck8 小时前
FortiWeb CVE-2025-64446漏洞深入复现分析
网络·安全·iot
wanhengidc8 小时前
可持续性 云手机运行
运维·服务器·网络·安全·智能手机
txg6668 小时前
VulCNN:多视图图表征驱动的可扩展漏洞检测体系
人工智能·深度学习·安全·网络安全
AI周红伟9 小时前
周红伟:OpenClaw安全防控:OpenClaw+Skills+DeepSeek-V4大模型安全部署、实操和企业应用实操
人工智能·深度学习·安全·机器学习·语言模型·openclaw
AI周红伟9 小时前
周红伟:AI时代,苹果还行吗?
大数据·人工智能·安全·copilot·openclaw
醉颜凉9 小时前
Elasticsearch 安全组件详解:Search Guard 和 X-Pack Security 到底有什么区别?
大数据·安全·elasticsearch