Splunk is a log analytics tool. It is often used as a security information and business analytics tool. Splunk deployments will often house lots of sensitive data.

Discovery

Splunk is usually found in internal network often ran as root on Linux or SYSTEM on Windows. Typically ran on port 8000 and with default credentials of admin:changeme. It also has a management port on 8089 for communication with the Splunk REST API.

Enumeration

Splunk Enterprise trial once ended will convert to a free version which doesn’t require authentication.

Attacking

RCE can be gained by creating a custom application to run on Python, Batch, Bash, or Powershell scripts. Splunk comes with Python installed we can create a Splunk application that gives us remote code execution using Python or a Powershell script.

inputs.conf in scripts tells Splunk which scripts to run and any other conditions.

[script://./bin/rev.py]
disabled = 0  
interval = 10  
sourcetype = shell 
 
[script://.\bin\run.bat]
disabled = 0
sourcetype = shell
interval = 10

This tells the script to run and any other conditions.