mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-05-05 10:16:59 +00:00
add Scrapyd Unauthorized Access RCE
This commit is contained in:
parent
70eab3eceb
commit
edb4438a6a
9
Scrapyd/README.md
Normal file
9
Scrapyd/README.md
Normal file
@ -0,0 +1,9 @@
|
||||
# Scrapyd Unauthorized Access RCE
|
||||
|
||||
Scrapyd is a cloud service provided by the crawler framework scrapy. Users can deploy their own scrapy package to the cloud service, which is listening on port 6800 by default. If an attacker can access this port, he will be able to deploy malicious code to the server and gain server permissions.
|
||||
|
||||
**FOFA query rule**: [title=="Scrapyd"](https://fofa.so/result?qbase64=dGl0bGU9PSJTY3JhcHlkIg%3D%3D)
|
||||
|
||||
# Demo
|
||||
|
||||

|
BIN
Scrapyd/Scrapyd_Unauthorized_Access_RCE.gif
Normal file
BIN
Scrapyd/Scrapyd_Unauthorized_Access_RCE.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 666 KiB |
Loading…
x
Reference in New Issue
Block a user