8086 - Pentesting InfluxDB

基本信息
枚举
认证
手动枚举
显示数据库
显示表/测量
显示列/字段键
转储表
自动化身份验证

最后更新于


最后更新于
PORT STATE SERVICE VERSION
8086/tcp open http InfluxDB http admin 1.7.5# Try unauthenticated
influx -host 'host name' -port 'port #'
> use _internalinflux –username influx –password influx_pass> show databases
name: databases
name
----
telegraf
_internal> show measurements
name: measurements
name
----
cpu
disk
diskio
kernel
mem
processes
swap
system> show field keys
name: cpu
fieldKey fieldType
-------- ---------
usage_guest float
usage_guest_nice float
usage_idle float
usage_iowait float
name: disk
fieldKey fieldType
-------- ---------
free integer
inodes_free integer
inodes_total integer
inodes_used integer
[ ... more keys ...]select * from cpu
name: cpu
time cpu host usage_guest usage_guest_nice usage_idle usage_iowait usage_irq usage_nice usage_softirq usage_steal usage_system usage_user
---- --- ---- ----------- ---------------- ---------- ------------ --------- ---------- ------------- ----------- ------------ ----------
1497018760000000000 cpu-total ubuntu 0 0 99.297893681046 0 0 0 0 0 0.35105315947842414 0.35105315947842414
1497018760000000000 cpu1 ubuntu 0 0 99.69909729188728 0 0 0 0 0 0.20060180541622202 0.10030090270811101msf6 > use auxiliary/scanner/http/influxdb_enum