MSSQL ์‚ฌ์šฉ์ž ์œ ํ˜•

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๋‹ค์Œ ํ‘œ๋Š” docs์—์„œ ๊ฐ€์ ธ์˜จ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

์—ด ์ด๋ฆ„๋ฐ์ดํ„ฐ ์œ ํ˜•์„ค๋ช…
namesysname์ฃผ์ฒด์˜ ์ด๋ฆ„, ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋‚ด์—์„œ ๊ณ ์œ ํ•ฉ๋‹ˆ๋‹ค.
principal_idint์ฃผ์ฒด์˜ ID, ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋‚ด์—์„œ ๊ณ ์œ ํ•ฉ๋‹ˆ๋‹ค.
typechar(1)

์ฃผ์ฒด ์œ ํ˜•:

A = ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์—ญํ• 

C = ์ธ์ฆ์„œ์— ๋งคํ•‘๋œ ์‚ฌ์šฉ์ž

E = Azure Active Directory์˜ ์™ธ๋ถ€ ์‚ฌ์šฉ์ž

G = Windows ๊ทธ๋ฃน

K = ๋น„๋Œ€์นญ ํ‚ค์— ๋งคํ•‘๋œ ์‚ฌ์šฉ์ž

R = ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์—ญํ• 

S = SQL ์‚ฌ์šฉ์ž

U = Windows ์‚ฌ์šฉ์ž

X = Azure Active Directory ๊ทธ๋ฃน ๋˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ์™ธ๋ถ€ ๊ทธ๋ฃน

type_descnvarchar(60)

์ฃผ์ฒด ์œ ํ˜•์— ๋Œ€ํ•œ ์„ค๋ช….

APPLICATION_ROLE

CERTIFICATE_MAPPED_USER

EXTERNAL_USER

WINDOWS_GROUP

ASYMMETRIC_KEY_MAPPED_USER

DATABASE_ROLE

SQL_USER

WINDOWS_USER

EXTERNAL_GROUPS

default_schema_namesysnameSQL ์ด๋ฆ„์ด ์Šคํ‚ค๋งˆ๋ฅผ ์ง€์ •ํ•˜์ง€ ์•Š์„ ๋•Œ ์‚ฌ์šฉํ•  ์ด๋ฆ„. S, U ๋˜๋Š” A ์œ ํ˜•์ด ์•„๋‹Œ ์ฃผ์ฒด์˜ ๊ฒฝ์šฐ Null์ž…๋‹ˆ๋‹ค.
create_datedatetime์ฃผ์ฒด๊ฐ€ ์ƒ์„ฑ๋œ ์‹œ๊ฐ„์ž…๋‹ˆ๋‹ค.
modify_datedatetime์ฃผ์ฒด๊ฐ€ ๋งˆ์ง€๋ง‰์œผ๋กœ ์ˆ˜์ •๋œ ์‹œ๊ฐ„์ž…๋‹ˆ๋‹ค.
owning_principal_idint์ด ์ฃผ์ฒด๋ฅผ ์†Œ์œ ํ•˜๋Š” ์ฃผ์ฒด์˜ ID. ๋ชจ๋“  ๊ณ ์ • ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์—ญํ• ์€ ๊ธฐ๋ณธ์ ์œผ๋กœ dbo๊ฐ€ ์†Œ์œ ํ•ฉ๋‹ˆ๋‹ค.
sidvarbinary(85)์ฃผ์ฒด์˜ SID(๋ณด์•ˆ ์‹๋ณ„์ž). SYS ๋ฐ INFORMATION SCHEMAS์˜ ๊ฒฝ์šฐ NULL์ž…๋‹ˆ๋‹ค.
is_fixed_rolebit1์ธ ๊ฒฝ์šฐ, ์ด ํ–‰์€ ๊ณ ์ • ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์—ญํ•  ์ค‘ ํ•˜๋‚˜์— ๋Œ€ํ•œ ํ•ญ๋ชฉ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค: db_owner, db_accessadmin, db_datareader, db_datawriter, db_ddladmin, db_securityadmin, db_backupoperator, db_denydatareader, db_denydatawriter.
authentication_typeint

์ ์šฉ ๋Œ€์ƒ: SQL Server 2012 (11.x) ๋ฐ ์ดํ›„ ๋ฒ„์ „.

์ธ์ฆ ์œ ํ˜•์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ๊ฐ€๋Šฅํ•œ ๊ฐ’๊ณผ ๊ทธ ์„ค๋ช…์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

0 : ์ธ์ฆ ์—†์Œ
1 : ์ธ์Šคํ„ด์Šค ์ธ์ฆ
2 : ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์ธ์ฆ
3 : Windows ์ธ์ฆ
4 : Azure Active Directory ์ธ์ฆ

authentication_type_descnvarchar(60)

์ ์šฉ ๋Œ€์ƒ: SQL Server 2012 (11.x) ๋ฐ ์ดํ›„ ๋ฒ„์ „.

์ธ์ฆ ์œ ํ˜•์— ๋Œ€ํ•œ ์„ค๋ช…. ๊ฐ€๋Šฅํ•œ ๊ฐ’๊ณผ ๊ทธ ์„ค๋ช…์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

NONE : ์ธ์ฆ ์—†์Œ
INSTANCE : ์ธ์Šคํ„ด์Šค ์ธ์ฆ
DATABASE : ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์ธ์ฆ
WINDOWS : Windows ์ธ์ฆ
EXTERNAL: Azure Active Directory ์ธ์ฆ

default_language_namesysname

์ ์šฉ ๋Œ€์ƒ: SQL Server 2012 (11.x) ๋ฐ ์ดํ›„ ๋ฒ„์ „.

์ด ์ฃผ์ฒด์˜ ๊ธฐ๋ณธ ์–ธ์–ด๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.

default_language_lcidint

์ ์šฉ ๋Œ€์ƒ: SQL Server 2012 (11.x) ๋ฐ ์ดํ›„ ๋ฒ„์ „.

์ด ์ฃผ์ฒด์˜ ๊ธฐ๋ณธ LCID๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.

allow_encrypted_value_modificationsbit

์ ์šฉ ๋Œ€์ƒ: SQL Server 2016 (13.x) ๋ฐ ์ดํ›„ ๋ฒ„์ „, SQL Database.

๋Œ€๋Ÿ‰ ๋ณต์‚ฌ ์ž‘์—…์—์„œ ์„œ๋ฒ„์˜ ์•”ํ˜ธํ™” ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ๊ฒ€์‚ฌ๋ฅผ ์–ต์ œํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ์‚ฌ์šฉ์ž๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ๋ณตํ˜ธํ™”ํ•˜์ง€ ์•Š๊ณ ๋„ Always Encrypted๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์•”ํ˜ธํ™”๋œ ๋ฐ์ดํ„ฐ๋ฅผ ํ…Œ์ด๋ธ” ๋˜๋Š” ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๊ฐ„์— ๋Œ€๋Ÿ‰ ๋ณต์‚ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ๊ฐ’์€ OFF์ž…๋‹ˆ๋‹ค.

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ