daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

memcache-commands.md (10804B)


      1 ---
      2 title: "Memcache Commands"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/11211-memcache/memcache-commands.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/11211-memcache/memcache-commands.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Memcache Commands
     14 
     15 ## Commands Cheat-Sheet
     16 
     17 **From** [**https://lzone.de/cheat-sheet/memcached**](https://lzone.de/cheat-sheet/memcached)<sup>[[1]](#references)</sup>
     18 
     19 The supported commands (the official ones and some unofficial) are documented in the [doc/protocol.txt](https://github.com/memcached/memcached/blob/master/doc/protocol.txt) document.
     20 
     21 Sadly the syntax description isn’t really clear and a simple help command listing the existing commands would be much better. Here is an overview of the commands you can find in the [source](https://github.com/memcached/memcached) (as of 19.08.2016):
     22 
     23 | Command              | Description                                                     | Example                                                                                                                                                                                                     |
     24 | -------------------- | --------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------- |
     25 | get                  | Reads a value                                                   | `get mykey`                                                                                                                                                                                                 |
     26 | set                  | Set a key unconditionally                                       | <p><code>set mykey <flags> <ttl> <size></code><br><br><p>Ensure to use \r\n als line breaks when using Unix CLI tools. For example</p> <code>printf "set mykey 0 60 4\r\ndata\r\n" | nc localhost 11211</code></p> |
     27 | add                  | Add a new key                                                   | `add newkey 0 60 5`                                                                                                                                                                                         |
     28 | replace              | Overwrite existing key                                          | `replace key 0 60 5`                                                                                                                                                                                        |
     29 | append               | Append data to existing key                                     | `append key 0 60 15`                                                                                                                                                                                        |
     30 | prepend              | Prepend data to existing key                                    | `prepend key 0 60 15`                                                                                                                                                                                       |
     31 | incr                 | Increments numerical key value by given number                  | `incr mykey 2`                                                                                                                                                                                              |
     32 | decr                 | Decrements numerical key value by given number                  | `decr mykey 5`                                                                                                                                                                                              |
     33 | delete               | Deletes an existing key                                         | `delete mykey`                                                                                                                                                                                              |
     34 | flush_all            | Invalidate all items immediately                                | `flush_all`                                                                                                                                                                                                 |
     35 | flush_all            | Invalidate all items in n seconds                               | `flush_all 900`                                                                                                                                                                                             |
     36 | stats                | Prints general statistics                                       | `stats`                                                                                                                                                                                                     |
     37 |                      | Prints memory statistics                                        | `stats slabs`                                                                                                                                                                                               |
     38 |                      | Print higher level allocation statistics                        | `stats malloc`                                                                                                                                                                                              |
     39 |                      | Print info on items                                             | `stats items`                                                                                                                                                                                               |
     40 |                      |                                                                 | `stats detail`                                                                                                                                                                                              |
     41 |                      |                                                                 | `stats sizes`                                                                                                                                                                                               |
     42 |                      | Resets statistics counters                                      | `stats reset`                                                                                                                                                                                               |
     43 | lru_crawler metadump | Dump (most of) the metadata for (all of) the items in the cache | `lru_crawler metadump all`                                                                                                                                                                                  |
     44 | version              | Prints server version.                                          | `version`                                                                                                                                                                                                   |
     45 | verbosity            | Increases log level                                             | `verbosity`                                                                                                                                                                                                 |
     46 | quit                 | Terminate session                                               | `quit`                                                                                                                                                                                                      |
     47 
     48 #### Traffic Statistics <a href="#traffic-statistics" id="traffic-statistics"></a>
     49 
     50 You can query the current traffic statistics using the command
     51 
     52 ```text
     53 stats
     54 ```
     55 
     56 You will get a listing which serves the number of connections, bytes in/out and much more.
     57 
     58 Example Output:
     59 
     60 ```text
     61 STAT pid 14868
     62 STAT uptime 175931
     63 STAT time 1220540125
     64 STAT version 1.2.2
     65 STAT pointer_size 32
     66 STAT rusage_user 620.299700
     67 STAT rusage_system 1545.703017
     68 STAT curr_items 228
     69 STAT total_items 779
     70 STAT bytes 15525
     71 STAT curr_connections 92
     72 STAT total_connections 1740
     73 STAT connection_structures 165
     74 STAT cmd_get 7411
     75 STAT cmd_set 28445156
     76 STAT get_hits 5183
     77 STAT get_misses 2228
     78 STAT evictions 0
     79 STAT bytes_read 2112768087
     80 STAT bytes_written 1000038245
     81 STAT limit_maxbytes 52428800
     82 STAT threads 1
     83 END
     84 ```
     85 
     86 #### Memory Statistics <a href="#memory-statistics" id="memory-statistics"></a>
     87 
     88 You can query the current memory statistics using
     89 
     90 ```text
     91 stats slabs
     92 ```
     93 
     94 Example Output:
     95 
     96 ```text
     97 STAT 1:chunk_size 80
     98 STAT 1:chunks_per_page 13107
     99 STAT 1:total_pages 1
    100 STAT 1:total_chunks 13107
    101 STAT 1:used_chunks 13106
    102 STAT 1:free_chunks 1
    103 STAT 1:free_chunks_end 12886
    104 STAT 2:chunk_size 100
    105 STAT 2:chunks_per_page 10485
    106 STAT 2:total_pages 1
    107 STAT 2:total_chunks 10485
    108 STAT 2:used_chunks 10484
    109 STAT 2:free_chunks 1
    110 STAT 2:free_chunks_end 10477
    111 [...]
    112 STAT active_slabs 3
    113 STAT total_malloced 3145436
    114 END
    115 ```
    116 
    117 If you are unsure if you have enough memory for your memcached instance always look out for the “evictions” counters given by the “stats” command. If you have enough memory for the instance the “evictions” counter should be 0 or at least not increasing.
    118 
    119 #### Which Keys Are Used? <a href="#which-keys-are-used" id="which-keys-are-used"></a>
    120 
    121 There is no builtin function to directly determine the current set of keys. However you can use the
    122 
    123 ```text
    124 stats items
    125 ```
    126 
    127 command to determine how many keys do exist.
    128 
    129 ```text
    130 stats items
    131 STAT items:1:number 220
    132 STAT items:1:age 83095
    133 STAT items:2:number 7
    134 STAT items:2:age 1405
    135 [...]
    136 END
    137 ```
    138 
    139 This at least helps to see if any keys are used. To dump the key names from a PHP script that already does the memcache access you can use the PHP code from [100days.de](http://100days.de/serendipity/archives/55-Dumping-MemcacheD-Content-Keys-with-PHP.html).<sup>[[2]](#references)</sup>
    140 
    141 ## References
    142 
    143 - [1] [Memcached Cheat Sheet - lzone.de](https://lzone.de/cheat-sheet/memcached)
    144 - [2] [Dumping MemcacheD Content Keys with PHP - 100days.de](http://100days.de/serendipity/archives/55-Dumping-MemcacheD-Content-Keys-with-PHP.html)