Skip to content
← LibraryTechnique entry
DB-REDIS-RCEExecution

Redis Unauth → RCE via CONFIG

Authless Redis on 6379 — CONFIG SET dir, dbfilename, then SAVE to write an SSH authorized_key / cron / webshell.

§ Where this technique fits

DB-REDIS-RCE is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 1×