diff --git a/.github/conf/.goreleaser.yml b/.github/conf/.goreleaser.yml index b4583c8..3babf90 100644 --- a/.github/conf/.goreleaser.yml +++ b/.github/conf/.goreleaser.yml @@ -17,9 +17,9 @@ builds: - "386" - arm - arm64 - - mips - - mipsle - - mips64 +# - mips +# - mipsle +# - mips64 goarm: - "6" - "7" diff --git a/WebScan/pocs/etcd-v3-unauth.yml b/WebScan/pocs/etcd-v3-unauth.yml index 1245900..d9a87d2 100644 --- a/WebScan/pocs/etcd-v3-unauth.yml +++ b/WebScan/pocs/etcd-v3-unauth.yml @@ -1,12 +1,14 @@ -name: poc-yaml-etcd-v3-unauth +name: ETCD V3未授权 rules: - - method: GET - path: /version + - method: POST + path: /v3/kv/range follow_redirects: false + Content-Type: application/json;charset=utf-8 expression: | - response.status == 200 && response.body.bcontains(b"etcdserver") - + response.status == 200 && response.body.bcontains(b"cluster") && response.body.bcontains(b"head") + body: | + {"key": "bmFtZQ=="} detail: author: rj45(https://github.com/INT2ECALL) links: - - https://networksec.blog.csdn.net/article/details/144912358?spm=1001.2014.3001.5502 \ No newline at end of file + - https://networksec.blog.csdn.net/article/details/144912358?spm=1001.2014.3001.5502