Saltstack

an open-source infrastructure automation and configuration management tool. Pull based model with agents (minions)

4505/tcp - ZeroMQ Sub channel

4506/tcp - ZeroMQ Req channel, the main channel to communicate with salt-master

8000/tcp (optional) - salt-master REST API. Almost all endpoints require eauth (e.g. PAM) authorization

Check unauth api

ZeroMQ sploit

PoC exploit for CVE-2020-11651 and CVE-2020-11652

another one

Chaining CVE-2021-25281 and CVE-2021-25282

Login bypass & arbitrary file write

Goals:

  • ssh key

  • cron job

  • register rogue minion

Register minion

compose

./minion

Last updated