Goby/json/Docker_Registry_API_Unauth....

103 lines
3.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Name": "Docker Registry API Unauth",
"Level": "2",
"Tags": [
"unauth"
],
"GobyQuery": "header=\"registry/2.0\"",
"Description": "Docker Registry API 存在未授权访问漏洞黑客可通过API下载docker images导致敏感信息泄露。",
"Product": "Docker Registry",
"Homepage": "https://docs.docker.com/registry/",
"Author": "aetkrad",
"Impact": "",
"Recommendation": "",
"References": [
"https://www.freeaihub.com/post/6085.html"
],
"HasExp": false,
"ExpParams": null,
"ExpTips": {
"Type": "",
"Content": ""
},
"ScanSteps": [
"AND",
{
"Request": {
"method": "GET",
"uri": "/v2/",
"follow_redirect": false,
"header": null,
"data_type": "text",
"data": "",
"set_variable": []
},
"ResponseTest": {
"type": "group",
"operation": "AND",
"checks": [
{
"type": "item",
"variable": "$code",
"operation": "==",
"value": "200",
"bz": ""
},
{
"type": "item",
"variable": "$head",
"operation": "contains",
"value": "docker-distribution-api-version",
"bz": ""
},
{
"type": "item",
"variable": "$head",
"operation": "contains",
"value": "registry/2.0",
"bz": ""
}
]
},
"SetVariable": [
"output|lastbody|regex|"
]
},
{
"Request": {
"method": "GET",
"uri": "/v2/_catalog",
"follow_redirect": true,
"header": null,
"data_type": "text",
"data": "",
"set_variable": []
},
"ResponseTest": {
"type": "group",
"operation": "AND",
"checks": [
{
"type": "item",
"variable": "$code",
"operation": "==",
"value": "200",
"bz": ""
},
{
"type": "item",
"variable": "$body",
"operation": "contains",
"value": "repositories",
"bz": ""
}
]
},
"SetVariable": [
"output|lastbody|regex|"
]
}
],
"PostTime": "2021-11-27 14:21:33",
"GobyVersion": "1.9.310"
}