9042 - Cassandra
💡 学习提示: 本文档介绍 Cassandra 的渗透测试方法,适合信息安全初学者和从业人员参考。
⚠️ 法律声明: 本文档仅供学习和授权测试使用。未经授权的系统测试可能违反法律法规。
⚠️ 法律声明: 本文档仅供学习和授权测试使用。未经授权的系统测试可能违反法律法规。
9042/9160 - 渗透测试 Cassandra
基本信息
Apache Cassandra is a highly scalable, high-performance distributed database designed to handle large amounts of data across many commodity servers, providing high availability with no single point of failure. It is a type of NoSQL database.
In several cases, you may find that Cassandra accepts any credentials (as there aren’t any configured) and this could potentially allow an attacker to enumerate the database.
默认 port: 9042,9160
信息收集
Manual
Automated
There aren’t much options here and nmap doesn’t obtain much info
Brute force
Shodan
port:9160 Cluster
port:9042 "Invalid or unsupported protocol version"