2024-04-09 17:38:47 +00:00
id : intelbras-dvr-unauth
2024-04-10 05:57:55 +00:00
2024-04-09 17:38:47 +00:00
info :
name : Intelbras DVR - Unrestricted Access
author : pussycat0x
severity : low
description : |
The HTTP GET request to /cap.js on the server Intelbras DVR reveals several potentially sensitive pieces of information that are not properly protected or encrypted.
reference :
- https://github.com/netsecfish/intelbras_cap_js
metadata :
verified : true
2024-06-07 10:04:29 +00:00
max-request : 1
fofa-query : "body=\"Intelbras\""
2024-04-09 17:38:47 +00:00
tags : unauth,intelbras,dvr,misconfig
http :
- method : GET
path :
- "{{BaseURL}}/cap.js"
2024-04-10 06:06:03 +00:00
matchers-condition : and
2024-04-09 17:38:47 +00:00
matchers :
- type : word
words :
- "var talkTypes="
- "var userInfo="
condition : and
- type : status
status :
- 200
2024-06-08 16:02:17 +00:00
# digest: 490a00463044022077d5d1b902ad52b3226bffb1c6932c3ea938ff178fbf2125c0188685fbff38d0022066fb0937444d9aca9350bbcbd4c4bbe1aa9c92bd5e3295b45072eb27db979280:922c64590222798bb761d5b6d8e72950