ESXi is reached through SSH and the ESXi Shell, the host client and vSphere API on 443, and the DCUI. Control of the host is control of every VM on it. Credentials come from brute-forcing or spraying root, from a compromised vCenter (which stores the per-host vpxuser password it uses to manage each host), or from host config backups.
ssh root@<esxi> # ESXi Shell
vim-cmd vmsvc/getallvms # list VMs
vim-cmd vmsvc/power.off <vmid> # control a VM
esxcli system account list # local accounts
# vSphere API over 443 (pyVmomi, govc) with host or vpxuser creds
govc ls -u 'root:pass@<esxi>' -k /
Exploitation notes#
- A compromised vCenter yields
vpxusercredentials for every managed host, so vCenter-to-ESXi is a one-step pivot; see vCenter. - From the shell,
vim-cmdand the datastore give console access and directVMDKaccess for Datastore and VMDK theft. - ESXi mass-encryption intrusions typically start exactly here: SSH or API access, then encrypt datastores.