Elasticsearch - Port 9200
Basic info
What is Elasticsearch?
The Elastic Stack (ELK)
Data Model
Inverted Index
Use Cases
Default Port
Reconnaissance & Enumeration
Port Scanning
Banner Grabbing
Shodan Queries
Authentication Testing
Check Authentication Status
Default Credentials
Brute Force Authentication
Enumeration Techniques
Cluster Information
Index Enumeration
User & Role Enumeration
API Endpoint Discovery
Data Exfiltration
Search and Dump Data
Dump Entire Index
Dump All Indices
Search for Sensitive Data
Exploitation Techniques
Unauthorized Data Modification
Code Execution via Scripts
Known Vulnerabilities & CVEs
CVE-2014-3120: Remote Code Execution (Groovy)
CVE-2015-1427: Groovy Sandbox Bypass
CVE-2021-22145: Denial of Service
CVE-2023-31419: Authentication Bypass
Directory Traversal (Various Versions)
Post-Exploitation
Privilege Escalation
Persistence
Lateral Movement
Defense & Hardening
Enable Authentication
Network Security
Disable Dangerous Features
Monitoring & Detection
Regular Security Practices
Tools & Scripts
Essential Tools
Python Enumeration Script
Cheat Sheet
Quick Reference
Important Endpoints
Default Credentials
Conclusion
Additional Resources
PreviousPJL (Printer Job Language) - Port 9100NextNetwork Data Management Protocol (NDMP) - PORT 10000
Last updated