nuclei-templates/default-logins/dell/dell-idrac9-default-login.yaml

43 lines
1.0 KiB
YAML

id: dell-idrac9-default-login
info:
name: DELL iDRAC9 Default Login
author: kophjager007,milo2012
severity: high
description: DELL iDRAC9 default login information was discovered. The default iDRAC username and password are widely known, and any user with access to the server could change the default password.
reference:
- https://www.dell.com/support/kbdoc/en-us/000177787/how-to-change-the-default-login-password-of-the-idrac-9
classification:
cwe-id: cwe-798
tags: dell,idrac,default-login
requests:
- raw:
- |
POST /sysmgmt/2015/bmc/session HTTP/1.1
Host: {{Hostname}}
User: "{{username}}"
Password: "{{password}}"
payloads:
username:
- root
password:
- calvin
attack: pitchfork
matchers-condition: and
matchers:
- type: status
status:
- 201
- 200
condition: or
- type: word
part: body
words:
- '"authResult":0'
# Enhanced by mp on 2022/03/03