Back to services
monitoring8000/tcp

Splunk

SplunkSIEMLog Management

Splunk is a SIEM and log analytics platform. RCE via custom app deployment, insecure search head configurations, and credential extraction from saved searches.

Ports

PortProtocolDescription
8000tcpSplunk web UI
8089tcpSplunk management
9997tcpSplunk forwarding

Fingerprints

Banner / ProbeExpected Response
nmap -sV -p <port> <target>Service banner and version info
nc -nv <target> <port>Raw banner grab

Key Files

PathDescription
.envEnvironment variables with API keys and DB creds
config.phpApplication configuration file
wp-config.phpWordPress database credentials
web.configIIS configuration file
.git/configGit repository configuration
robots.txtDisallowed paths (information disclosure)
sitemap.xmlURL structure enumeration

Default Credentials

UsernamePasswordContext
adminadminGeneric admin account
rootrootGeneric root account

Known CVEs

IdentifierTypeDescription
CVE-2023-46214RCESplunk Enterprise RCE

Exploitation Primitives

TechniqueTool / CommandResult
Reconnmap -sV -sC -p- <target>Full port/service scan
Enumerationnmap --script <service>-* -p <port> <target>Service-specific NSE scripts

Notes

Always start with full port scan: `nmap -sV -sC -p- <target>`.

Check for default credentials before brute-forcing.

Use service-specific NSE scripts: `nmap --script <service>-* -p <port> <target>`.

Remember to check both IPv4 and IPv6 if applicable.

Seen on

ShodanCensysFOFAZoomEye

References