Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

听说有nps鉴权绕过漏洞 #1090

Open
Deep0 opened this issue Jul 29, 2022 · 11 comments
Open

听说有nps鉴权绕过漏洞 #1090

Deep0 opened this issue Jul 29, 2022 · 11 comments
Labels
bug Something isn't working

Comments

@Deep0
Copy link

Deep0 commented Jul 29, 2022

web/controllers/base.go
听说是auth_key鉴权漏洞,请作者核实一下?

@Deep0 Deep0 added the bug Something isn't working label Jul 29, 2022
@hongcaohu
Copy link

也收到了漏洞通知

@crazyNing
Copy link

我刚刚复现了,但是没看出来利用价值,每次请求带auth_key可以成功访问页面,但是管理好像不行,没深入看

@lishiren-admin
Copy link

注释掉auth_key就行了

@Is4b3lla3
Copy link

注释掉auth_key就行了

应该是去掉authkey的注释

@lishiren-admin
Copy link

不用去掉注释,把 auth_key 和auth_crypt_key 同时注释即可

@JAXo-China
Copy link

然并卵?

@Jireh012
Copy link

https://jireh.xyz/articles/2022/08/10/1660122191957.html

@carr0t2
Copy link

carr0t2 commented Aug 19, 2022

@suka23333
Copy link

是不是还有其它漏洞,按照教程修复了,有个叼毛还能一直RDP攻击我,擦

@JAXo-China
Copy link

是不是还有其它漏洞,按照教程修复了,有个叼毛还能一直RDP攻击我,擦

跟你一样,CPU飙起来。。。

@yisier
Copy link

yisier commented Dec 30, 2022

https://github.com/yisier/nps/releases/tag/v0.26.14

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

10 participants