工具项目
文集大纲加载中……
小迪安全知识库
-
+
首页
Nacos综合漏洞利用工具
Nacos综合漏洞利用工具
# NacosExploit 项目地址:https://github.com/h0ny/NacosExploit [](https://github.com/h0ny/NacosExploit#nacosexploit) ### 一款 Nacos 综合漏洞利用工具 ## 支持漏洞 | PoC | Exploit | 漏洞名称 | 漏洞编号 | |-----|---------|-----------------------------|------------------| | ✅ | ✅ | Nacos 默认关闭认证 | / | | ✅ | ✅ | Nacos 默认密码 (nacos/nacos) | AVD-2021-896025 | | ✅ | ✅ | Nacos 默认 server.identity | / | | ✅ | ✅ | Nacos 默认 token.secret.key | AVD-2023-1655789 | | ✅ | ✅ | Nacos 默认 User-Agent | AVD-2021-29441 | | ✅ | ✅ | Nacos Derby SQL Injection | AVD-2021-897468 | | / | ✅ | Nacos JRaft Hessian 反序列化 | AVD-2023-1700159 | | / | ✅ | Nacos JRaft Services 文件操作漏洞 | AVD-2024-1743586 | ### 漏洞检测 [](https://github.com/h0ny/NacosExploit#%E6%BC%8F%E6%B4%9E%E6%A3%80%E6%B5%8B) [](https://github.com/h0ny/NacosExploit/blob/main/README.assets/1.png) ### 认证绕过 [](https://github.com/h0ny/NacosExploit#%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87) [](https://github.com/h0ny/NacosExploit/blob/main/README.assets/2.png) ### Derby SQL 注入 [](https://github.com/h0ny/NacosExploit#derby-sql-%E6%B3%A8%E5%85%A5) [](https://github.com/h0ny/NacosExploit/blob/main/README.assets/3.png) ### Jraft 反序例化 [](https://github.com/h0ny/NacosExploit#jraft-%E5%8F%8D%E5%BA%8F%E4%BE%8B%E5%8C%96) RCE: [](https://github.com/h0ny/NacosExploit/blob/main/README.assets/4.png) 文件读取: [](https://github.com/h0ny/NacosExploit/blob/main/README.assets/5.png) ### 加解密支持 [](https://github.com/h0ny/NacosExploit#%E5%8A%A0%E8%A7%A3%E5%AF%86%E6%94%AF%E6%8C%81) [](https://github.com/h0ny/NacosExploit/blob/main/README.assets/6.png) ### 批量任务 [](https://github.com/h0ny/NacosExploit#%E6%89%B9%E9%87%8F%E4%BB%BB%E5%8A%A1) [](https://github.com/h0ny/NacosExploit/blob/main/README.assets/7.png)
xiaodi
2026年9月17日 15:52
5
0 条评论
转发
收藏文档
上一篇
下一篇
手机扫码
复制链接
手机扫一扫转发分享
复制链接
分享
链接
类型
密码
更新密码
有效期
Markdown文件
Word文件
PDF文档
PDF文档(打印)