Pentesting Grafana
Source: https://rootxsushant.medium.com/a-comprehensive-guide-for-pentesting-grafana-cfa09b2f1243
Grafana is an open source interactive data-visualization platform, developed by Grafana Labs, which allows users to see their data via charts and graphs that are unified into one dashboard (or multiple dashboards!) for easier interpretation and understanding. You can also query and set alerts on your information and metrics from wherever that information is stored, whether that’s traditional server environments, Kubernetes clusters, or various cloud services, etc.
Important grafana files and directories
grafana.db
Save to your local machine.
If you have SQLite installed, just run:
Once inside the shell:
Default Credentials
Grafana, like many other platforms, often ships with preset login credentials that administrators may forget to update.
Tools
grafana2hashcat: Original | My fork