Influxdb 认证绕过漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# When all else fails - find a 0-day How a failing red-team engagement led us to find a silly zero day. And why “insecure by default” is still an issue in 2019. In early 2019 we conducted a red-team engagement for a security tech company that, well, knows how to secure stuff. The scope excluded social engineering or any physical attacks against the office network, so we were left with only the internet-facing attack surface. Confident and proud, we found 2 SQL Injections and an RCE in a matter of hours. We broke into the network and gained access to the most sensitive internal DB packed with consumer data. Actually, none of that happened. The company did a fantastic job with securing their perimeter, after all - they are a security vendor. **Exposed DB - a new hope?** The company did however have an InfluxDB cluster open to the internet. It was protected by a password and all attempts to brute force it failed. So we did the only thing desperate hackers can do: find a 0-day in...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息