Rocket.Chat is a Node.js application built on the Meteor framework, serving a web client and a REST API rooted at /api/v1 on port 3000 by default (commonly proxied to 443), with Meteor's DDP protocol over a /sockjs/ websocket and MongoDB underneath. The MongoDB backing and Meteor's permissive handling of request bodies drive the signature attack: the login endpoint accepts a structured object where a string is expected, so a Mongo query operator injected into user or password turns authentication into a query that matches without the real password. Hold any admin token and the admin-only integrations feature runs server-side JavaScript in a sandbox that has repeatedly been escapable to require/process, which is the route to code execution as the Node user.
Fingerprint first#
Confirm the product and pin the build, because the login-bypass behavior and the integration-script sandbox differ by version.
curl -sk http://<target>:3000/api/info
# {"version":"6.5.0","success":true} confirms Rocket.Chat + exact version
curl -skI http://<target>:3000/sockjs/info # Meteor/SockJS transport (DDP) present
curl -skI http://<target>:3000/ | grep -i x-instance-id # X-Instance-Id header is Rocket.Chat
/api/info gives the version with no authentication on most builds; where it is locked down, the Meteor bootstrap data in the page source and the __meteor_runtime_config__ blob still leak the release. Note whether /api/v1/settings.public is reachable unauthenticated (below) because it exposes whether registration is open and which login methods are enabled. Record the version before attacking the login layer.
Pages#
- Enumeration: harvesting users and channels through
/api/v1/users.list,/api/v1/channels.list, and/api/v1/spotlight, readingsettings.public, and using the Meteor DDP methods; interpreting the JSON returned withX-Auth-Token/X-User-Idheaders. - Authentication: why the REST
/api/v1/loginresists a naive operator object, the blind NoSQL injection in the account and reset methods that extracts a stored password-reset token to take over an admin, and the Enterpriseddp-streamerusername-lookup bypass. - Server exploitation: chaining the auth bypass to an admin token, then the incoming/outgoing integration "script" and webhook sandbox escape to
require/processfor code execution, the file-upload sink, and the message-parser SSRF; ending in a shell as the node user.