meshcentral.md (6710B)
1 --- 2 title: "MeshCentral" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/meshcentral.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/meshcentral.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # MeshCentral 14 15 ## Overview 16 17 **MeshCentral** is a self-hosted remote monitoring / device management platform that mixes an **admin web UI** with **agent-facing WebSocket endpoints**. During a pentest, treat it as both a **web target** and an **RMM control plane**: a single browser-side bug in the dashboard can become **fleet-wide command execution** because the product already exposes legitimate remote execution features. 18 19 Relevant endpoints from the public exploit chain:<sup>[[1]](#references)</sup> 20 21 - Admin UI: `https://<target>/` 22 - Agent channel: `wss://<target>/agent.ashx` 23 - Admin control channel: `wss://<target>/control.ashx` 24 25 If you identify MeshCentral, review the generic [XSS](/hacktricks/pentesting-web/xss-cross-site-scripting/overview) and [WebSocket Attacks](/hacktricks/pentesting-web/websocket-attacks) pages, then test how **agent-controlled metadata** reaches the UI and how the UI talks to privileged WebSocket APIs. 26 27 ## High-value attack surface 28 29 ### 1. Agent-submitted metadata rendered in the admin UI 30 31 Do not limit testing to normal dashboard users. MeshCentral agents submit host metadata that is later rendered to administrators, so fields such as **device name**, **OS description**, **volume labels**, **sensor names**, or similar agent-fed attributes should be treated as **stored XSS candidates**.<sup>[[2]](#references)</sup> 32 33 In the published 2026 chain, a rogue/compromised agent injected HTML/JS into `osdesc` inside the `coreinfo` message. When an admin opened the device details panel, the payload executed in the admin origin.<sup>[[1]](#references)[[2]](#references)</sup> 34 35 ## Agent impersonation from a low-privileged host 36 37 If you compromise a managed endpoint, check whether local users can read MeshCentral enrollment material. In the public advisory chain, **low-privileged Windows users** could read `MeshAgent.msh` and `MeshAgent.db`, which exposed enough data to impersonate the enrolled node:<sup>[[3]](#references)</sup> 38 39 - Server URL / WebSocket endpoint 40 - MeshID / ServerID / NodeID 41 - Agent certificate and private key material 42 43 Typical extraction flow:<sup>[[3]](#references)</sup> 44 45 ```bash 46 uv run extract_agent_identity.py /path/to/MeshCentral/ -o client.json 47 uv run rogue_agent.py -s mesh.lab.local --identity client.json 48 ``` 49 50 This is a useful pattern beyond MeshCentral: whenever an RMM/MDM agent stores **tenant identifiers**, **node identity**, or **client certificates/keys** in locally readable files, a local foothold may be enough to **re-register or impersonate** the device remotely. 51 52 ## MeshCentral agent authentication flow 53 54 When emulating a MeshAgent, the public PoC used the following handshake against `/agent.ashx`:<sup>[[3]](#references)</sup> 55 56 1. Connect and recover the TLS certificate hash. 57 2. Send **Cmd 1** with a nonce and cert hash. 58 3. Send **Cmd 4** to trust the server / skip its signature validation. 59 4. Receive server **Cmd 1** nonce. 60 5. Send **Cmd 2** with the agent certificate and **RSA-SHA384** signature. 61 6. Send **Cmd 3** with agent info / metadata. 62 7. Wait for **Cmd 4** to confirm authentication. 63 64 Once authenticated, an attacker-controlled agent can update metadata fields that later reach the UI. 65 66 ## Stored XSS -> privileged WebSocket API abuse 67 68 The important escalation is not the alert box. The key trick is that **same-origin JavaScript executing in the MeshCentral admin console can open the privileged WebSocket API with the victim admin session automatically attached by the browser**.<sup>[[1]](#references)</sup> 69 70 Minimal browser primitive:<sup>[[1]](#references)</sup> 71 72 ```javascript 73 const ws = new WebSocket(location.origin.replace(/^http/, 'ws') + '/control.ashx') 74 ``` 75 76 From there, the published chain waited for `serverinfo`, enumerated nodes, and then used the built-in remote execution action:<sup>[[1]](#references)</sup> 77 78 ```javascript 79 ws.send(JSON.stringify({action:'nodes',responseid:'poc'})) 80 ws.send(JSON.stringify({ 81 action:'runcommands', 82 nodeids:[nodeId], 83 type:0, 84 cmds:'whoami > C:\\pwned.txt', 85 runAsUser:0, 86 responseid:'rce-'+nodeId 87 })) 88 ``` 89 90 Important fields:<sup>[[1]](#references)</sup> 91 92 - `action:'nodes'`: enumerate devices visible to the admin session 93 - `action:'runcommands'`: dispatch remote commands through the management plane 94 - `type:0`: `cmd` / shell 95 - `type:2`: PowerShell 96 - `runAsUser:0`: request execution as **SYSTEM/root** 97 98 This is the general RMM/MDM lesson: **stored XSS in a management console is often equivalent to authenticated API abuse and remote code execution** because the platform already exposes privileged operator actions.<sup>[[1]](#references)</sup> 99 100 ## Pentest checklist 101 102 - Fingerprint MeshCentral and inspect both `/agent.ashx` and `/control.ashx` traffic. 103 - Test whether **agent-controlled fields** are reflected in device details, sharing dialogs, file-browser metadata, or permission dialogs. 104 - On a compromised endpoint, check ACLs on **`MeshAgent.msh`** and **`MeshAgent.db`**. 105 - If the browser UI uses WebSockets, capture the JSON actions and replay them after achieving XSS. 106 - Check whether remote execution features allow **SYSTEM/root** execution (`runAsUser:0`). 107 - Review command history/logs for suspicious `runcommands`, broad node enumeration, or the same command sent to many devices. 108 109 ## Mitigation / detection notes 110 111 - **Upgrade MeshCentral to 1.1.60 or later**. Publicly documented affected versions are **below 1.1.60**.<sup>[[2]](#references)[[4]](#references)</sup> 112 - Defenders should review MeshCentral logs for:<sup>[[1]](#references)</sup> 113 - unexpected `runcommands` 114 - suspicious `runAsUser:0` 115 - one admin session enumerating many nodes immediately before command dispatch 116 - demo artifacts such as `whoami > C:\\pwned.txt` 117 118 ## References 119 120 - [1] [MeshCentral: From Agent-Controlled Stored XSS to Fleet-Wide RCE](https://techanarchy.net/meshcentral-from-xss-to-rce) 121 - [2] [MeshCentral security advisory – stored XSS via unsanitized osdesc field (GHSA-c7hr-448w-65px)](https://github.com/Ylianst/MeshCentral/security/advisories/GHSA-c7hr-448w-65px) 122 - [3] [MeshCentral-RogueAgent – agent identity extraction and impersonation PoC](https://github.com/kevthehermit/MeshCentral-RogueAgent) 123 - [4] [MeshCentral fix PR #7823](https://github.com/Ylianst/MeshCentral/pull/7823)