Nagios is a long-standing monitoring system in two forms: the open-source Nagios Core (configured by files, with a CGI web interface) and the commercial Nagios XI (a full PHP web application on top). Icinga is a fork with Icinga 2 and the Icinga Web 2 interface. They monitor hosts by running check plugins locally and, for remote hosts, through NRPE (the Nagios Remote Plugin Executor) on TCP 5666. The attack surface: the web interface authentication, the NRPE agent which executes check commands and is a classic command-injection target, injection into the Nagios command and macro definitions that run on the monitoring server, and the long list of Nagios XI web-application vulnerabilities that chain authentication bypass to remote code execution.
# web interfaces and the NRPE agent
curl -sk https://<target>/nagios/ ; curl -sk https://<target>/nagiosxi/
nmap -p5666 -sV <target> # NRPE
Subtopics#
- Enumeration: product and version fingerprinting.
- Authentication: default and weak web credentials.
- NRPE abuse: the remote plugin executor on 5666.
- Command and plugin injection: injection into command definitions.
- Nagios XI exploits: the auth-bypass-to-RCE chains.