Unauthenticated Access to Kong API Metrics
by Evil_BYTE_Officiel - 15-08-25, 02:39 AM
#1
Hi EvilByte with You ! 

Today I present : Herriot Watt University , Unprotected Kong Api Metrics !

[Image: main-reception-statue.xf49a521a.png?w=80...0&fit=crop]


Target_access : https://portal.hw.ac.uk/metrics/


What You can DO ? :

[*]Pulls
Code:
/metrics

[*]Extracts all service names


[*]leaks:
  • Internal service hostnames
  • Route paths
  • Workspace names
  • Usernames
  • Traffic patterns


[*]Discover internal hostnames (
Code:
alerts-api
,
Code:
files-api
,
Code:
identity-services
…)
[*]Learn directory structure and routes for other APIs
[*]Identify admin dashboards like
Code:
grafana
,
Code:
kibana
,
Code:
consul-ui

[*]Enumerate users (
Code:
dave.forrester
) for targeted attacks
[*]Guess high-traffic endpoints for exploitation priority

[*]Its For Free ! Kisses

[*]Best Regards, EvilByte

[*]Telegram : https://t.me/EVILbyteOFFICIEL

[*]Catgun
Reply


Forum Jump:


 Users browsing this thread: 1 Guest(s)