Instant messaging

Real-time messaging servers split into two attack models. The open protocols (IRC, XMPP, Matrix) are attacked on the wire: you speak the protocol to enumerate the server, abuse its services and federation, and exploit the daemon. The self-hosted team-chat platforms (Mattermost, Rocket.Chat) are attacked as web applications: REST and websocket APIs where the weaknesses are authentication bypass, authorization gaps, injection, and integration or plugin code execution.

Triage#

bash
nmap -sV -p6667,6697,5222,5223,5269,8008,8448,8065,3000 <target>
#  6667/6697 IRC   5222/5269 XMPP   8008/8448 Matrix   8065 Mattermost   3000 Rocket.Chat
curl -s http://<target>:8065/api/v4/system/ping        # Mattermost
curl -s http://<target>:3000/api/info                  # Rocket.Chat
curl -s https://<target>/_matrix/client/versions       # Matrix homeserver

An IRC/XMPP/Matrix port routes to Protocols; a Mattermost or Rocket.Chat web app routes to Team-chat platforms.

Subtopics#

  • Protocols: IRC, XMPP, and Matrix, attacked on the wire from enumeration through server exploitation.
  • Team-chat platforms: self-hosted Mattermost and Rocket.Chat, attacked through their web APIs.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more