Redis - Port 6379
Basic info
What is Redis?
Redis Architecture
Redis Communication Protocol
Default Port
Authentication Models
Databases in Redis
Reconnaissance & Enumeration
Port Scanning
Automated Enumeration
Manual Enumeration
Banner Grabbing
Shodan Queries
Authentication Testing
Check Authentication Requirements
Password Brute Force
Authentication
Enumeration (Authenticated)
Get Server Information
Configuration Enumeration
Client Enumeration
Monitor Commands
Database Enumeration
Dumping the Database
Exploitation Techniques
1. Webshell Upload (PHP)
2. Template Engine Injection
3. SSH Key Injection
4. Crontab Injection
5. Redis Module Loading (RCE)
6. Master-Slave Replication Abuse
7. Lua Sandbox Escape
8. Recent Lua CVEs (2025)
9. SSRF to Redis
Post-Exploitation
Data Exfiltration
Persistence
Lateral Movement
Defense & Hardening
Secure Configuration
Network Security
Monitoring & Detection
Regular Security Tasks
Tools & Scripts
Essential Tools
Custom Scripts
Cheat Sheet
Quick Reference
Important Configs
Common Paths
Conclusion
Additional Resources
Last updated