daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

meshcentral.md (6710B)


      1 ---
      2 title: "MeshCentral"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/meshcentral.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/meshcentral.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # MeshCentral
     14 
     15 ## Overview
     16 
     17 **MeshCentral** is a self-hosted remote monitoring / device management platform that mixes an **admin web UI** with **agent-facing WebSocket endpoints**. During a pentest, treat it as both a **web target** and an **RMM control plane**: a single browser-side bug in the dashboard can become **fleet-wide command execution** because the product already exposes legitimate remote execution features.
     18 
     19 Relevant endpoints from the public exploit chain:<sup>[[1]](#references)</sup>
     20 
     21 - Admin UI: `https://<target>/`
     22 - Agent channel: `wss://<target>/agent.ashx`
     23 - Admin control channel: `wss://<target>/control.ashx`
     24 
     25 If you identify MeshCentral, review the generic [XSS](/hacktricks/pentesting-web/xss-cross-site-scripting/overview) and [WebSocket Attacks](/hacktricks/pentesting-web/websocket-attacks) pages, then test how **agent-controlled metadata** reaches the UI and how the UI talks to privileged WebSocket APIs.
     26 
     27 ## High-value attack surface
     28 
     29 ### 1. Agent-submitted metadata rendered in the admin UI
     30 
     31 Do not limit testing to normal dashboard users. MeshCentral agents submit host metadata that is later rendered to administrators, so fields such as **device name**, **OS description**, **volume labels**, **sensor names**, or similar agent-fed attributes should be treated as **stored XSS candidates**.<sup>[[2]](#references)</sup>
     32 
     33 In the published 2026 chain, a rogue/compromised agent injected HTML/JS into `osdesc` inside the `coreinfo` message. When an admin opened the device details panel, the payload executed in the admin origin.<sup>[[1]](#references)[[2]](#references)</sup>
     34 
     35 ## Agent impersonation from a low-privileged host
     36 
     37 If you compromise a managed endpoint, check whether local users can read MeshCentral enrollment material. In the public advisory chain, **low-privileged Windows users** could read `MeshAgent.msh` and `MeshAgent.db`, which exposed enough data to impersonate the enrolled node:<sup>[[3]](#references)</sup>
     38 
     39 - Server URL / WebSocket endpoint
     40 - MeshID / ServerID / NodeID
     41 - Agent certificate and private key material
     42 
     43 Typical extraction flow:<sup>[[3]](#references)</sup>
     44 
     45 ```bash
     46 uv run extract_agent_identity.py /path/to/MeshCentral/ -o client.json
     47 uv run rogue_agent.py -s mesh.lab.local --identity client.json
     48 ```
     49 
     50 This is a useful pattern beyond MeshCentral: whenever an RMM/MDM agent stores **tenant identifiers**, **node identity**, or **client certificates/keys** in locally readable files, a local foothold may be enough to **re-register or impersonate** the device remotely.
     51 
     52 ## MeshCentral agent authentication flow
     53 
     54 When emulating a MeshAgent, the public PoC used the following handshake against `/agent.ashx`:<sup>[[3]](#references)</sup>
     55 
     56 1. Connect and recover the TLS certificate hash.
     57 2. Send **Cmd 1** with a nonce and cert hash.
     58 3. Send **Cmd 4** to trust the server / skip its signature validation.
     59 4. Receive server **Cmd 1** nonce.
     60 5. Send **Cmd 2** with the agent certificate and **RSA-SHA384** signature.
     61 6. Send **Cmd 3** with agent info / metadata.
     62 7. Wait for **Cmd 4** to confirm authentication.
     63 
     64 Once authenticated, an attacker-controlled agent can update metadata fields that later reach the UI.
     65 
     66 ## Stored XSS -> privileged WebSocket API abuse
     67 
     68 The important escalation is not the alert box. The key trick is that **same-origin JavaScript executing in the MeshCentral admin console can open the privileged WebSocket API with the victim admin session automatically attached by the browser**.<sup>[[1]](#references)</sup>
     69 
     70 Minimal browser primitive:<sup>[[1]](#references)</sup>
     71 
     72 ```javascript
     73 const ws = new WebSocket(location.origin.replace(/^http/, 'ws') + '/control.ashx')
     74 ```
     75 
     76 From there, the published chain waited for `serverinfo`, enumerated nodes, and then used the built-in remote execution action:<sup>[[1]](#references)</sup>
     77 
     78 ```javascript
     79 ws.send(JSON.stringify({action:'nodes',responseid:'poc'}))
     80 ws.send(JSON.stringify({
     81   action:'runcommands',
     82   nodeids:[nodeId],
     83   type:0,
     84   cmds:'whoami > C:\\pwned.txt',
     85   runAsUser:0,
     86   responseid:'rce-'+nodeId
     87 }))
     88 ```
     89 
     90 Important fields:<sup>[[1]](#references)</sup>
     91 
     92 - `action:'nodes'`: enumerate devices visible to the admin session
     93 - `action:'runcommands'`: dispatch remote commands through the management plane
     94 - `type:0`: `cmd` / shell
     95 - `type:2`: PowerShell
     96 - `runAsUser:0`: request execution as **SYSTEM/root**
     97 
     98 This is the general RMM/MDM lesson: **stored XSS in a management console is often equivalent to authenticated API abuse and remote code execution** because the platform already exposes privileged operator actions.<sup>[[1]](#references)</sup>
     99 
    100 ## Pentest checklist
    101 
    102 - Fingerprint MeshCentral and inspect both `/agent.ashx` and `/control.ashx` traffic.
    103 - Test whether **agent-controlled fields** are reflected in device details, sharing dialogs, file-browser metadata, or permission dialogs.
    104 - On a compromised endpoint, check ACLs on **`MeshAgent.msh`** and **`MeshAgent.db`**.
    105 - If the browser UI uses WebSockets, capture the JSON actions and replay them after achieving XSS.
    106 - Check whether remote execution features allow **SYSTEM/root** execution (`runAsUser:0`).
    107 - Review command history/logs for suspicious `runcommands`, broad node enumeration, or the same command sent to many devices.
    108 
    109 ## Mitigation / detection notes
    110 
    111 - **Upgrade MeshCentral to 1.1.60 or later**. Publicly documented affected versions are **below 1.1.60**.<sup>[[2]](#references)[[4]](#references)</sup>
    112 - Defenders should review MeshCentral logs for:<sup>[[1]](#references)</sup>
    113   - unexpected `runcommands`
    114   - suspicious `runAsUser:0`
    115   - one admin session enumerating many nodes immediately before command dispatch
    116   - demo artifacts such as `whoami > C:\\pwned.txt`
    117 
    118 ## References
    119 
    120 - [1] [MeshCentral: From Agent-Controlled Stored XSS to Fleet-Wide RCE](https://techanarchy.net/meshcentral-from-xss-to-rce)
    121 - [2] [MeshCentral security advisory – stored XSS via unsanitized osdesc field (GHSA-c7hr-448w-65px)](https://github.com/Ylianst/MeshCentral/security/advisories/GHSA-c7hr-448w-65px)
    122 - [3] [MeshCentral-RogueAgent – agent identity extraction and impersonation PoC](https://github.com/kevthehermit/MeshCentral-RogueAgent)
    123 - [4] [MeshCentral fix PR #7823](https://github.com/Ylianst/MeshCentral/pull/7823)