Kепloy 从 3.1.0 到 3.6.25 版本将 agent 控制平面 HTTP 服务器绑定到所有网络接口,且未进行身份验证,从而暴露了多个端点,这些端点用于流式传输 TLS 会话密钥和流量数据。攻击者可以访问 /agent/pcap/keylog 端点以获取 NSS keylog 行,从而解密已录制的 TLS 流量;或调用 /agent/stop 和 /agent/storemocks 端点来操控录制会话。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet