daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cassandra.md (4455B)


      1 ---
      2 title: "9042, 9160 - Pentesting Cassandra"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/cassandra.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/cassandra.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 9042, 9160 - Pentesting Cassandra
     14 
     15 ## Basic Information
     16 
     17 **Apache Cassandra** is a distributed NoSQL database designed to store data across multiple nodes without a single point of failure.<sup>[[1]](#references)</sup>
     18 
     19 The native CQL protocol listens on TCP port **9042** by default. TCP port **9160** belongs to the legacy Thrift RPC service; in Cassandra 3.11 it is disabled by default, and modern deployments normally use the native protocol.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     20 
     21 Historically, Cassandra's default `AllowAllAuthenticator` required no credentials. An exposed cluster with authentication disabled may therefore allow schema and data access, not merely credential guessing. Cassandra's security documentation recommends configuring authentication, authorization, and encryption together.<sup>[[3]](#references)</sup>
     22 
     23 **Default/legacy ports:** 9042/TCP (native CQL), 9160/TCP (legacy Thrift)
     24 
     25 ```text
     26 PORT     STATE SERVICE   REASON
     27 9042/tcp open  cassandra-native Apache Cassandra 3.10 or later (native protocol versions 3/v3, 4/v4, 5/v5-beta)
     28 9160/tcp open  cassandra syn-ack
     29 ```
     30 
     31 ## Enumeration
     32 
     33 ### Manual
     34 
     35 ```sql
     36 cqlsh <IP> 9042
     37 
     38 -- Basic node information
     39 SELECT cluster_name, data_center, rack, partitioner, native_protocol_version, release_version FROM system.local;
     40 
     41 -- Older releases may also expose Thrift-specific version information
     42 SELECT thrift_version FROM system.local;
     43 
     44 -- Keyspace enumeration on current releases
     45 SELECT keyspace_name FROM system_schema.keyspaces;
     46 SELECT keyspace_name FROM system.schema_keyspaces; -- Cassandra 2.x and older
     47 DESCRIBE KEYSPACES;
     48 DESCRIBE KEYSPACE <keyspace_name>;
     49 DESCRIBE KEYSPACE system_auth;
     50 
     51 -- Role metadata, if the connected role is authorized to read it
     52 SELECT role, is_superuser, can_login FROM system_auth.roles;
     53 SELECT * FROM system_auth.roles;  -- May include password hashes in the configured backend
     54 
     55 -- Application-specific tables discovered during keyspace enumeration
     56 SELECT * FROM logdb.user_auth;
     57 SELECT * FROM logdb.user;
     58 SELECT * FROM configuration."config";
     59 ```
     60 
     61 The `logdb` and `configuration` queries are examples from real deployments, not built-in Cassandra schemas. Run them only if enumeration shows those keyspaces and tables; otherwise, adapt the query to the application's discovered schema.
     62 
     63 `cqlsh` ships with Cassandra and connects to one specified node through the native protocol. If the matching client is not otherwise available, a standalone package can be installed with `python3 -m pip install cqlsh`, but compatibility is guaranteed only between the `cqlsh` version and the Cassandra version with which it was released.<sup>[[4]](#references)[[6]](#references)</sup>
     64 
     65 ### Automated
     66 
     67 Nmap's `cassandra-info` script attempts to retrieve basic server status. Its documented example targets the legacy Thrift service on port 9160, so it is not a replacement for CQL enumeration on port 9042.<sup>[[5]](#references)</sup>
     68 
     69 ```bash
     70 nmap -sV --script cassandra-info -p <PORT> <IP>
     71 ```
     72 
     73 ### [**Brute force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#cassandra)
     74 
     75 ### **Shodan**
     76 
     77 `port:9160 Cluster`\
     78 `port:9042 "Invalid or unsupported protocol version"`
     79 
     80 ## References
     81 
     82 - [1] [Apache Cassandra FAQ - Default ports](https://cassandra.apache.org/doc/stable/cassandra/overview/faq/index.html#what-ports-does-cassandra-use)
     83 - [2] [Apache Cassandra 3.11 configuration - Thrift and native transport](https://cassandra.apache.org/doc/3.11/cassandra/configuration/cass_yaml_file.html)
     84 - [3] [Apache Cassandra documentation - Security](https://cassandra.apache.org/doc/stable/cassandra/managing/operating/security.html)
     85 - [4] [Apache Cassandra documentation - cqlsh](https://cassandra.apache.org/doc/stable/cassandra/managing/tools/cqlsh.html)
     86 - [5] [Nmap NSE documentation - cassandra-info](https://nmap.org/nsedoc/scripts/cassandra-info.html)
     87 - [6] [PyPI - standalone `cqlsh` package](https://pypi.org/project/cqlsh/)