nuclei-templates/default-logins/apache/ranger-default-login.yaml

40 lines
790 B
YAML

id: ranger-default-login
info:
name: Apache Ranger Default Login
author: For3stCo1d
severity: high
reference: https://github.com/apache/ranger
metadata:
shodan-query: http.title:"Ranger - Sign In"
tags: apache,ranger,default-login
requests:
- raw:
- |
POST /login HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
username={{user}}&password={{pass}}
attack: pitchfork
payloads:
user:
- admin
pass:
- admin
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"statusCode":200'
- '"msgDesc":"Login Successful"'
condition: and
- type: status
status:
- 200