
https://github.com/AbelChe/evil_minio/tree/main 打包留存
https://github.com/AbelChe/evil_minio/tree/main Original project repository Personal packaging archive Affected versions: 2019-12-17T23-16-33Z to RELEASE.2023-03-20T20-16-18Z
Reproduction: https://www.yuque.com/jason-soozc/luhd40/pgabr9xvg0kgx85v?singleDoc# "MinIO unauthorized access to RCE, cluster mode"
GLOBAL backdoor as http://1.2.3.4/?alive=whoami and http://1.2.3.4/anything?alive=whoami

Disclaimer: This tool is only for security research purposes. Do not use it for illegal testing. Any direct or indirect consequences and losses caused by the dissemination or use of the information provided in this document shall be borne by the user. The author assumes no responsibility for this.