AWS - MQ Unauthenticated Enum

Reading time: 2 minutes

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks

Porti ya Umma

RabbitMQ

Katika kesi ya RabbitMQ, kwa chaguo-msingi public access na ssl zimewezeshwa. Lakini unahitaji credentials ili kupata (amqps://.mq.us-east-1.amazonaws.com:5671). Zaidi ya hayo, inawezekana kuingia kwenye web management console ikiwa unajua credentials katika https://b-<uuid>.mq.us-east-1.amazonaws.com/

ActiveMQ

Katika kesi ya ActiveMQ, kwa chaguo-msingi public access na ssl zimewezeshwa, lakini unahitaji credentials ili kupata.

Kiolezo cha URL ya Umma

https://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:8162/
ssl://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:61617

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks