module

Multi Gather Ubiquiti UniFi Controller Backup

Disclosed
N/A
Created
May 15, 2019

Description

On an Ubiquiti UniFi controller, reads the system.properties configuration file
and downloads the backup and autobackup files. The files are then decrypted using
a known encryption key, then attempted to be repaired by zip. Meterpreter must be
used due to the large file sizes, which can be flaky on regular shells to read.
Confirmed to work on 5.10.19 - 5.10.23, but most likely quite a bit more.
If the zip can be repaired, the db and its information will be extracted.

Authors

h00die
zhangyoufu
justingist

Platform

Linux,OSX,Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use post/multi/gather/ubiquiti_unifi_backup
msf post(ubiquiti_unifi_backup) > show actions
...actions...
msf post(ubiquiti_unifi_backup) > set ACTION < action-name >
msf post(ubiquiti_unifi_backup) > show options
...show and set options...
msf post(ubiquiti_unifi_backup) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.