AWS - MQ Unauthenticated Enum

Reading time: 2 minutes

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks

Public Port

RabbitMQ

Katika kesi ya RabbitMQ, kwa kawaida ufikiaji wa umma na ssl vimewezeshwa. Lakini unahitaji akikazi ili kufikia (amqps://.mq.us-east-1.amazonaws.com:5671​​). Zaidi ya hayo, inawezekana kufikia konsoli ya usimamizi wa wavuti ikiwa unajua akiba katika https://b-<uuid>.mq.us-east-1.amazonaws.com/

ActiveMQ

Katika kesi ya ActiveMQ, kwa kawaida ufikiaji wa umma na ssl vimewezeshwa, lakini unahitaji akiba ili kufikia.

Public URL template

https://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:8162/
ssl://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:61617

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks