Real-time messaging servers split into two attack models. The open protocols (IRC, XMPP, Matrix) are attacked on the wire: you speak the protocol to enumerate the server, abuse its services and federation, and exploit the daemon. The self-hosted team-chat platforms (Mattermost, Rocket.Chat) are attacked as web applications: REST and websocket APIs where the weaknesses are authentication bypass, authorization gaps, injection, and integration or plugin code execution.
Triage#
nmap -sV -p6667,6697,5222,5223,5269,8008,8448,8065,3000 <target>
# 6667/6697 IRC 5222/5269 XMPP 8008/8448 Matrix 8065 Mattermost 3000 Rocket.Chat
curl -s http://<target>:8065/api/v4/system/ping # Mattermost
curl -s http://<target>:3000/api/info # Rocket.Chat
curl -s https://<target>/_matrix/client/versions # Matrix homeserver
An IRC/XMPP/Matrix port routes to Protocols; a Mattermost or Rocket.Chat web app routes to Team-chat platforms.
Subtopics#
- Protocols: IRC, XMPP, and Matrix, attacked on the wire from enumeration through server exploitation.
- Team-chat platforms: self-hosted Mattermost and Rocket.Chat, attacked through their web APIs.