Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/mihneamanolache/redis-exploit
A proof of concept illustrating the risks of unauthenticated Redis servers. Learn about potential data theft from openly accessible Redis installations. Educational use only. Use responsibly.
https://github.com/mihneamanolache/redis-exploit
Last synced: 17 days ago
JSON representation
A proof of concept illustrating the risks of unauthenticated Redis servers. Learn about potential data theft from openly accessible Redis installations. Educational use only. Use responsibly.
- Host: GitHub
- URL: https://github.com/mihneamanolache/redis-exploit
- Owner: mihneamanolache
- License: mit
- Created: 2023-05-17T09:32:20.000Z (over 1 year ago)
- Default Branch: main
- Last Pushed: 2024-03-13T07:33:58.000Z (10 months ago)
- Last Synced: 2024-11-05T19:48:54.503Z (2 months ago)
- Language: Rust
- Size: 22.5 KB
- Stars: 0
- Watchers: 1
- Forks: 2
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
README
# Redis Exploit
- **Exploit Title: Redis Unauthnticated Access**
- **Date:17.05.2023**
- **Exploit Authors: [Mihnea Octavian Manolache](https://github.com/mihneamanolache)**
- **Vendor Homepage: https://redis.io/**
- **CVE: n/a**
- **Research Paper: https://mihnea.hashnode.dev/vulnerability-report-redis-exploit**## **IMPORTANT NOTICE**
This vulnerability underscores the importance for server owners to implement authentication on their Redis servers if the service is installed on their machines. When Redis servers are publicly accessible over the internet without proper SASL authentication configuration, anyone who can establish a connection to the server gains unrestricted access to the stored data. This exposes the risk of attackers being able to manipulate or delete data and potentially steal sensitive information such as login credentials for web applications or customer data from online shops. It is crucial for server owners to prioritize implementing authentication measures to protect against such security breaches.Please note that this vulnerability is not inherent to the Redis service itself, but rather the lack of proper authentication implementation by server owners. Redis provides authentication mechanisms that can be configured to enhance the security of your Redis servers. You can find more information about Redis Authentication [here](https://redis.io/commands/auth/).
## Instalation and Usage
To install the exploit, download the latest [Release](https://github.com/mihneamanolache/redis-exploit/releases/) from GitHub, or run the following commands:
```bash
# Install redis-exploit locally
sudo curl https://raw.githubusercontent.com/mihneamanolache/redis-exploit/main/install.sh | sh# Run the exploit on an IP range
redis-exploit 0.0.0.0/24
```
![Exploit running](https://cdn.hashnode.com/res/hashnode/image/upload/v1684485847855/e8b06d55-8e80-4b50-8b44-d5d09d538d07.gif?w=1600&h=840&fit=crop&crop=entropy&auto=format,compress&gif-q=60&format=webm)## Disclaimer
The following proof of concept code demonstrates the potential risks associated with Redis servers that lack proper authentication. The code will be made available on my GitHub repository for educational purposes only. It is essential to note that the intention behind sharing this code is to raise awareness about the importance of implementing security measures and to promote responsible and ethical behavior in the field of cybersecurity.I want to emphasize that the use of this code for any illegal or unauthorized activities is strictly prohibited. It is the responsibility of each individual to comply with applicable laws and regulations in their respective jurisdictions. Engaging in any unauthorized access, data theft, or malicious activities is against the law and can result in severe legal consequences.
By accessing and utilizing the code from the GitHub repository, you agree that I am not liable or responsible for any misuse or illegal activities conducted with the provided code. It is your responsibility to use this knowledge and code responsibly and in an ethical manner.
I strongly encourage users to apply these learnings in a legal and ethical manner to enhance their understanding of security vulnerabilities and to take appropriate measures to secure their own systems and networks.
Remember, cybersecurity is a shared responsibility, and we must all work together to create a safer digital environment.
**Please use this code responsibly and ethically.**