Splunk

Splunk exploitation

Discovery/Footprinting

The Splunk web server runs by default on port 8000. On older versions of Splunk, the default credentials are admin:changeme

If the default credentials do not work, it is worth checking for common weak passwords such as admin, Welcome, Welcome1, Password123, etc.

Enumeration

The Splunk Enterprise trial converts to a free version after 60 days, which doesn’t require authentication.

Abusing Built-In Functionality

See OffShore WU

Reverse shell

Windows

run.ps1

.bat file

Linux

Edit the rev.py Python script before creating the tarball and uploading the custom malicious app

CVE-2024-36991 - Read /etc/passwd

Exploit

Splunk

Resources

Interesting Books

Interesting Books

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Last updated