Redis Webroot Rce

Windows/Linux 场景下基于 Redis 未授权访问写入 Web 根并获取稳定命令执行、随后快速收敛到 NPS 的专项技能。只要用户提到 Redis、Redis未授权、6379、fscan 提示 unauthorized file、CONFIG SET dir/dbfilename、写 webshell、写计划任务、写 ssh key,或者已经确认 Redis 能写入 Web 目录,就应优先使用本技能,而不是走泛化 Web 利用或 SMB 分支。尤其在用户已经有上游跳板、NPS 通道、HTTP 映射端口时,必须优先触发本技能。

m-sec-org Updated

File contents

m-sec-org/breachweave/tree/main/packages/core/src/config/skills/builtin/redis-webroot-rce commit 194853e593

Frequently asked questions

npx skillmds@latest add m-sec-org/redis-webroot-rce