daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (9569B)


      1 ---
      2 title: "11211 - Pentesting Memcache"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/11211-memcache/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/11211-memcache/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 11211 - Pentesting Memcache
     14 
     15 ## Protocol Information
     16 
     17 **Memcached** is a distributed in-memory key/value cache commonly used to reduce repeated database or API work. Its servers are intentionally simple: clients choose a server, send a key, and receive or update the associated opaque value.<sup>[[5]](#references)</sup>
     18 
     19 Memcached's binary protocol can be built with **SASL** authentication, but authentication is not automatically enabled. Treat any reachable unauthenticated listener as an exposure and restrict the service to trusted networks.<sup>[[6]](#references)</sup><sup>[[7]](#references)</sup>
     20 
     21 **Default port:** 11211
     22 
     23 ```text
     24 PORT      STATE SERVICE
     25 11211/tcp open  unknown
     26 ```
     27 
     28 ## Enumeration
     29 
     30 ### Manual
     31 
     32 To enumerate information saved inside a Memcached instance:
     33 
     34 1. Find **slabs** with **active items**
     35 2. Get the **key names** of the slabs detected before
     36 3. Retrieve the **saved data** by requesting the discovered keys
     37 
     38 Remember that this service is just a **cache**, so **data may be appearing and disappearing**.
     39 
     40 ```bash
     41 echo "version" | nc -vn -w 1 <IP> 11211      #Get version
     42 echo "stats" | nc -vn -w 1 <IP> 11211        #Get status
     43 echo "stats slabs" | nc -vn -w 1 <IP> 11211  #Get slabs
     44 echo "stats items" | nc -vn -w 1 <IP> 11211  #Get items of slabs with info
     45 echo "stats cachedump <number> 0" | nc -vn -w 1 <IP> 11211  #Get key names (the 0 is for unlimited output size)
     46 echo "get <item_name>" | nc -vn -w 1 <IP> 11211  #Get saved info
     47 
     48 #This php will just dump the keys, you need to use "get <item_name> later"
     49 sudo apt-get install php-memcached
     50 php -r '$c = new Memcached(); $c->addServer("localhost", 11211); var_dump( $c->getAllKeys() );'
     51 ```
     52 
     53 ### Manual2
     54 
     55 ```bash
     56 sudo apt install libmemcached-tools
     57 memcstat --servers=127.0.0.1 #Get stats
     58 memcdump --servers=127.0.0.1 #Get all items
     59 memccat  --servers=127.0.0.1 <item1> <item2> <item3> #Get info inside the item(s)
     60 ```
     61 
     62 ### Automatic
     63 
     64 ```bash
     65 nmap -n -sV --script memcached-info -p 11211 <IP>   #Just gather info
     66 msf > use auxiliary/gather/memcached_extractor      #Extracts saved data
     67 msf > use auxiliary/scanner/memcached/memcached_amp #Check is UDP DDoS amplification attack is possible
     68 ```
     69 
     70 ## **Dumping Memcached Keys**
     71 
     72 Memcached organizes items into slab classes. Historical diagnostic commands can reveal keys, but they have important constraints:<sup>[[1]](#references)</sup>
     73 
     74 1. Keys can only be dumped by slab class, grouping keys of similar content size.
     75 2. A limit exists of one page per slab class, equating to 1MB of data.
     76 3. `stats cachedump` is an unofficial, version-sensitive diagnostic command rather than a complete production-safe export mechanism.<sup>[[2]](#references)</sup>
     77 
     78 The limitation of only being able to dump 1MB from potentially gigabytes of data is particularly significant. However, this functionality can still offer insights into key usage patterns, depending on specific needs. For those less interested in the mechanics, a visit to the [tools section](https://lzone.de/cheat-sheet/memcached#tools) reveals utilities for comprehensive dumping. Alternatively, the process of using telnet for direct interaction with memcached setups is outlined below.<sup>[[1]](#references)</sup>
     79 
     80 ### **How it Works**
     81 
     82 Memcached's memory organization is pivotal. Starting Memcached with `-vv` reveals the slab classes it generates, as shown below:<sup>[[1]](#references)</sup>
     83 
     84 ```bash
     85 $ memcached -vv
     86 slab class   1: chunk size        96 perslab   10922
     87 [...]
     88 ```
     89 
     90 To display all currently existing slabs, the following command is used:
     91 
     92 ```bash
     93 stats slabs
     94 ```
     95 
     96 Adding a single key to memcached 1.4.13 illustrates how slab classes are populated and managed. For instance:
     97 
     98 ```bash
     99 set mykey 0 60 1
    100 1
    101 STORED
    102 ```
    103 
    104 Executing the "stats slabs" command post key addition yields detailed statistics about slab utilization:
    105 
    106 ```bash
    107 stats slabs
    108 [...]
    109 ```
    110 
    111 This output reveals the active slab types, utilized chunks, and operational statistics, offering insights into the efficiency of read and write operations.
    112 
    113 Another useful command, "stats items", provides data on evictions, memory constraints, and item lifecycles:
    114 
    115 ```bash
    116 stats items
    117 [...]
    118 ```
    119 
    120 These statistics allow for educated assumptions about application caching behavior, including cache efficiency for different content sizes, memory allocation, and capacity for caching large objects.
    121 
    122 ### **Dumping Keys**
    123 
    124 For versions prior to 1.4.31, keys are dumped by slab class using:
    125 
    126 ```bash
    127 stats cachedump <slab class> <number of items to dump>
    128 ```
    129 
    130 For example, to dump a key in class #1:
    131 
    132 ```bash
    133 stats cachedump 1 1000
    134 ITEM mykey [1 b; 1350677968 s]
    135 END
    136 ```
    137 
    138 This method iterates over slab classes, extracting and optionally dumping key values.
    139 
    140 ### **Dumping Memcached Keys (1.4.31+)**
    141 
    142 Memcached 1.4.31 introduced `lru_crawler metadump`, a non-blocking way to enumerate item metadata across slab classes. It may generate extensive output, so stream or filter the response rather than buffering it unnecessarily.<sup>[[3]](#references)</sup>
    143 
    144 ```bash
    145 echo 'lru_crawler metadump all' | nc 127.0.0.1 11211 | head -1
    146 echo 'lru_crawler metadump all' | nc 127.0.0.1 11211 | grep ee6ba58566e234ccbbce13f9a24f9a28
    147 ```
    148 
    149 ### **DUMPING TOOLS**
    150 
    151 Table [from here](https://lzone.de/blog).<sup>[[4]](#references)</sup>
    152 
    153 | Language/tool | Resource | Functionality |
    154 | --- | --- | --- |
    155 | PHP | [simple script](http://snipt.org/xtP) | Prints key names. |
    156 | Perl | [simple script](https://wiki.jasig.org/download/attachments/13572172/memcached-clean.pl?version=1&modificationDate=1229693957401) | Prints keys and values. |
    157 | Ruby | [simple script](https://gist.github.com/1365005) | Prints key names. |
    158 | Perl/libmemcached | [memdump](https://search.cpan.org/~dmaki/Memcached-libmemcached-0.4202/src/libmemcached/docs/memdump.pod) / [module](https://search.cpan.org/~dmaki/Memcached-libmemcached/) | Dumps keys through the CPAN module. |
    159 | PHP | [memcache.php](http://livebookmark.net/journal/2008/05/21/memcachephp-stats-like-apcphp/) | Historical monitoring GUI that can dump keys. |
    160 | libmemcached | [peep](http://blog.evanweaver.com/2009/04/20/peeping-into-memcached/) | Historical dumper that can freeze the Memcached process. Do not run it against production without explicit authorization and an outage plan. |
    161 
    162 ## Troubleshooting <a href="#troubleshooting" id="troubleshooting"></a>
    163 
    164 ### 1MB Data Limit <a href="#1mb-data-limit" id="1mb-data-limit"></a>
    165 
    166 The default maximum item size is 1 MiB. Modern Memcached versions can change it with the `-I` option, subject to server limits; do not infer a historical version solely from the 1 MiB default.<sup>[[8]](#references)</sup>
    167 
    168 ### Never Set a Timeout > 30 Days! <a href="#never-set-a-timeout--30-days" id="never-set-a-timeout--30-days"></a>
    169 
    170 For storage commands, expiration values up to 30 days are interpreted as relative seconds; larger values are interpreted as absolute Unix timestamps. A timestamp in the past expires the item immediately, which can look like a silent failure.<sup>[[6]](#references)</sup>
    171 
    172 So if you want to use the maximum lifetime specify 2592000. Example:
    173 
    174 ```text
    175 set my_key 0 2592000 1
    176 1
    177 ```
    178 
    179 ### Disappearing Keys on Overflow <a href="#disappearing-keys-on-overflow" id="disappearing-keys-on-overflow"></a>
    180 
    181 Counter behavior is implementation- and version-sensitive. If an `incr` operation causes a key to disappear in the tested version, recreate it with `add` or `set` and verify the result before relying on overflow behavior.<sup>[[1]](#references)</sup>
    182 
    183 ### Replication <a href="#replication" id="replication"></a>
    184 
    185 Memcached itself does not provide replication; the following historical or third-party projects offer related behavior.<sup>[[5]](#references)</sup>
    186 
    187 - [repcached](http://repcached.lab.klab.org/): Multi-master async replication (memcached 1.2 patch set)
    188 - [Couchbase memcached interface](http://www.couchbase.com/memcached): Use CouchBase as memcached drop-in
    189 - [yrmcds](https://cybozu.github.io/yrmcds/): Memcached-compatible primary/replica key-value store
    190 - [twemproxy](https://github.com/twitter/twemproxy) (aka nutcracker): proxy with memcached support
    191 
    192 ### Commands Cheat-Sheet
    193 
    194 
    195 [Memcache Commands](/hacktricks/network-services-pentesting/11211-memcache/memcache-commands)
    196 
    197 ### **Shodan**
    198 
    199 - `port:11211 "STAT pid"`
    200 - `"STAT pid"`
    201 
    202 ## References
    203 
    204 - [1] [Memcached Cheat Sheet](https://lzone.de/cheat-sheet/memcached)
    205 - [2] [Memcached "stats cachedump" discussion](https://groups.google.com/forum/?fromgroups=#!topic/memcached/1-T8I-RVGKM)
    206 - [3] [Release Notes for memcached 1.4.31 - lru_crawler metadump](https://github.com/memcached/memcached/wiki/ReleaseNotes1431)
    207 - [4] [LZone Blog - Memcached dumping tools](https://lzone.de/blog)
    208 - [5] [Memcached documentation: About Memcached](https://docs.memcached.org/)
    209 - [6] [Memcached protocol documentation](https://github.com/memcached/memcached/blob/master/doc/protocol.txt)
    210 - [7] [Memcached SASL documentation](https://github.com/memcached/memcached/wiki/SASLHowto)
    211 - [8] [Memcached server options (`-I` maximum item size)](https://github.com/memcached/memcached/blob/master/doc/memcached.1)