cassandra.md (4455B)
1 --- 2 title: "9042, 9160 - Pentesting Cassandra" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/cassandra.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/cassandra.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 9042, 9160 - Pentesting Cassandra 14 15 ## Basic Information 16 17 **Apache Cassandra** is a distributed NoSQL database designed to store data across multiple nodes without a single point of failure.<sup>[[1]](#references)</sup> 18 19 The native CQL protocol listens on TCP port **9042** by default. TCP port **9160** belongs to the legacy Thrift RPC service; in Cassandra 3.11 it is disabled by default, and modern deployments normally use the native protocol.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 20 21 Historically, Cassandra's default `AllowAllAuthenticator` required no credentials. An exposed cluster with authentication disabled may therefore allow schema and data access, not merely credential guessing. Cassandra's security documentation recommends configuring authentication, authorization, and encryption together.<sup>[[3]](#references)</sup> 22 23 **Default/legacy ports:** 9042/TCP (native CQL), 9160/TCP (legacy Thrift) 24 25 ```text 26 PORT STATE SERVICE REASON 27 9042/tcp open cassandra-native Apache Cassandra 3.10 or later (native protocol versions 3/v3, 4/v4, 5/v5-beta) 28 9160/tcp open cassandra syn-ack 29 ``` 30 31 ## Enumeration 32 33 ### Manual 34 35 ```sql 36 cqlsh <IP> 9042 37 38 -- Basic node information 39 SELECT cluster_name, data_center, rack, partitioner, native_protocol_version, release_version FROM system.local; 40 41 -- Older releases may also expose Thrift-specific version information 42 SELECT thrift_version FROM system.local; 43 44 -- Keyspace enumeration on current releases 45 SELECT keyspace_name FROM system_schema.keyspaces; 46 SELECT keyspace_name FROM system.schema_keyspaces; -- Cassandra 2.x and older 47 DESCRIBE KEYSPACES; 48 DESCRIBE KEYSPACE <keyspace_name>; 49 DESCRIBE KEYSPACE system_auth; 50 51 -- Role metadata, if the connected role is authorized to read it 52 SELECT role, is_superuser, can_login FROM system_auth.roles; 53 SELECT * FROM system_auth.roles; -- May include password hashes in the configured backend 54 55 -- Application-specific tables discovered during keyspace enumeration 56 SELECT * FROM logdb.user_auth; 57 SELECT * FROM logdb.user; 58 SELECT * FROM configuration."config"; 59 ``` 60 61 The `logdb` and `configuration` queries are examples from real deployments, not built-in Cassandra schemas. Run them only if enumeration shows those keyspaces and tables; otherwise, adapt the query to the application's discovered schema. 62 63 `cqlsh` ships with Cassandra and connects to one specified node through the native protocol. If the matching client is not otherwise available, a standalone package can be installed with `python3 -m pip install cqlsh`, but compatibility is guaranteed only between the `cqlsh` version and the Cassandra version with which it was released.<sup>[[4]](#references)[[6]](#references)</sup> 64 65 ### Automated 66 67 Nmap's `cassandra-info` script attempts to retrieve basic server status. Its documented example targets the legacy Thrift service on port 9160, so it is not a replacement for CQL enumeration on port 9042.<sup>[[5]](#references)</sup> 68 69 ```bash 70 nmap -sV --script cassandra-info -p <PORT> <IP> 71 ``` 72 73 ### [**Brute force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#cassandra) 74 75 ### **Shodan** 76 77 `port:9160 Cluster`\ 78 `port:9042 "Invalid or unsupported protocol version"` 79 80 ## References 81 82 - [1] [Apache Cassandra FAQ - Default ports](https://cassandra.apache.org/doc/stable/cassandra/overview/faq/index.html#what-ports-does-cassandra-use) 83 - [2] [Apache Cassandra 3.11 configuration - Thrift and native transport](https://cassandra.apache.org/doc/3.11/cassandra/configuration/cass_yaml_file.html) 84 - [3] [Apache Cassandra documentation - Security](https://cassandra.apache.org/doc/stable/cassandra/managing/operating/security.html) 85 - [4] [Apache Cassandra documentation - cqlsh](https://cassandra.apache.org/doc/stable/cassandra/managing/tools/cqlsh.html) 86 - [5] [Nmap NSE documentation - cassandra-info](https://nmap.org/nsedoc/scripts/cassandra-info.html) 87 - [6] [PyPI - standalone `cqlsh` package](https://pypi.org/project/cqlsh/)