Logstash is an open source tool for collecting, parsing, and storing logs for future use. Kibana is a web interface that can be used to search and view the logs that Logstash has indexed. Both of these tools are based on Elasticsearch. Elasticsearch, Logstash, and Kibana, when used together is known as an ELK stack.
Affected URL: http://<IP>:5601/api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../../<js file>
Affected Parameter: apis
Lets include this rshell.js file using the LFI in Kibana
After including our rshell.js file, we receive a reverse shell
We can also include a webshell instead which might help when we face firewall restrictions. In case we upload a webshell, here is how we can access the webshell and execute commands
js reverse shell and js webshell can be found at the following link: