Merge pull request #2496 from 1u4nx/master

Unauth ClickHouse database Disclosure
patch-1
Prince Chaddha 2021-08-27 13:29:09 +05:30 committed by GitHub
commit bd591cbffa
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 25 additions and 0 deletions

View File

@ -0,0 +1,25 @@
id: clickhouse-unauth
info:
name: Unauth ClickHouse Disclosure
author: lu4nx
severity: high
tags: network,clickhouse
network:
- inputs:
# 0011436c69636b486f75736520636c69656e741508b1a9030007 is header
# 64656661756c74 = default
- data: 0011436c69636b486f75736520636c69656e741508b1a903000764656661756c7400
type: hex
host:
- "{{Hostname}}"
- "{{Hostname}}:9000"
read-size: 100
matchers:
- type: word
words:
- "ClickHouse"