Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-9554 PoC — Synology DiskStation Manager 信息泄露漏洞

Source
Associated Vulnerability
Title:Synology DiskStation Manager 信息泄露漏洞 (CVE-2017-9554)
Description:Synology DiskStation Manager(DSM)是群晖科技(Synology)公司的一套用于网络储存服务器(NAS)上的操作系统。该操作系统可管理资料、文件、照片、音乐等信息。 Synology DSM 6.1.3-15152之前的版本中的forget_passwd.cgi文件存在信息泄露漏洞。远程攻击者可利用该漏洞枚举有效用户名。
Description
Tiny script to enumerate users using CVE-2017-9554 (forget_passwd.cgi) 
Readme
# Synology DiskStation User Enumeration (CVE-2017-9554)

Basic script to enumerate valid users on Synology DiskStation < v6.1.3-15152
File Snapshot

[4.0K] /data/pocs/37da2fe2293cf2c49927a156b8fb7384d5bd07aa ├── [1.2K] CVE-2017-9554.py └── [ 134] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.