> For the complete documentation index, see [llms.txt](https://lyethar.gitbook.io/sybaris/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://lyethar.gitbook.io/sybaris/exploitation.md).

# Exploitation

{% embed url="<https://book.hacktricks.xyz/network-services-pentesting/6379-pentesting-redis>" %}

Having both autenticated to redis and ftp it is dangerous practice to have them both open at the same time because with redis we can load modules directly from the folders that the ftp server runs.&#x20;

{% embed url="<https://github.com/n0b0dyCN/RedisModules-ExecuteCommand>" %}

Using this exploit. I used the command "make" to build the module.so that it is needed for this exploit.&#x20;

![](https://2613529462-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFXeC5YxTHfutkog2Ggfm%2Fuploads%2FBrBj736y1G0SNaILCtVd%2F2022-08-03_16-25.png?alt=media\&token=02262e17-56eb-4a0d-bab7-0e073f7bc69a)

After uploading the module.so to the pub directory all we had to do was go on google and look this up.

{% embed url="<https://www.linuxquestions.org/questions/red-hat-31/direct-access-on-pub-directory-for-anonymous-user-on-ftp-server-4175504168/>" %}

The pub directory in anonymous access in ftp is located in /var/ftp/pub/module.so

![](https://2613529462-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFXeC5YxTHfutkog2Ggfm%2Fuploads%2F3rDDU6o9DFoIPitcKYta%2F2022-08-03_16-28.png?alt=media\&token=41047b0b-72dd-4853-a275-8d980b1132c9)

![](https://2613529462-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFXeC5YxTHfutkog2Ggfm%2Fuploads%2FZFSOF1lynFHpO9myE13I%2F2022-08-03_16-30.png?alt=media\&token=119428e2-3a33-434e-8d70-91b46cb8ea6c)
