Elasticsearch Pentesting
Default Credentials
admin:elasticadmin
elastic:changemeBrute Force Credentials
hydra -L usernames.txt -P passwords.txt <target-ip> -s 9200 http-get /Common Directories
/_cat/
/_cat/indices
/_cluster/
/_nodes/
/_remote/
/_security
/_search?q=username
/_search?q=password
/_security/role
/_security/user
/_xpack/security/user/Last updated