Arsenale · Attacchi ai Database
DBMS esposti o raggiunti via SQLi: enumerazione, credenziali, lettura file e RCE. Tutorial injection: SQL Injection.
Solo su DB tuoi o in scope.
MySQL / MariaDB
| Tecnica | Come funziona | Tool / comando |
| Auth brute force | Password deboli/root vuota | hydra mysql |
| Version/enum | Versione, db, utenti | SELECT version() |
| File read | Leggi file col privilegio FILE | LOAD_FILE() |
| File write / webshell | Scrivi file nella webroot | INTO OUTFILE |
| UDF RCE | User Defined Function → comando OS | raptor_udf |
| Hash dump | Estrai gli hash utente | SELECT user,password FROM mysql.user |
| Privilege enum | Cosa può fare l'utente | SHOW GRANTS |
| Trigger backdoor | Persistenza via trigger | manuale |
MSSQL
| Tecnica | Come funziona | Tool / comando |
| Auth brute / login | sa e password deboli | mssqlclient.py |
| xp_cmdshell RCE | Esegui comandi OS | EXEC xp_cmdshell |
| Enable xp_cmdshell | Riattivalo via sp_configure | sp_configure |
| Linked servers | Pivot su altri DB fidati | OPENQUERY |
| Impersonation (EXECUTE AS) | Escalation a sysadmin | manuale |
| UNC hash capture | Forza auth verso responder | xp_dirtree |
| OLE automation RCE | Esecuzione via sp_OACreate | manuale |
| CLR assembly RCE | Carica assembly .NET | PowerUpSQL |
| Enum con PowerUpSQL | Scopri istanze e privilegi | PowerUpSQL |
| Trustworthy DB abuse | Escalation via db TRUSTWORTHY | manuale |
PostgreSQL
| Tecnica | Come funziona | Tool / comando |
| Auth brute | Password deboli | hydra postgres |
| COPY TO/FROM PROGRAM | Esegui comandi OS (9.3+) | COPY ... FROM PROGRAM |
| File read/write | pg_read_file / lo_export | manuale |
| Large object RCE | Scrivi librerie via LO | manuale |
| Privilege enum | Ruoli e permessi | \du |
| Extension RCE | Carica estensione malevola | manuale |
Oracle
| Tecnica | Come funziona | Tool / comando |
| TNS/SID enum | Scopri SID e listener | odat · tnscmd |
| Default credentials | scott/tiger, system | liste |
| PL/SQL injection | Escalation via package | manuale |
| File/OS via odat | Lettura file, RCE | odat |
| Password hash extraction | Dump degli hash | odat |
| Java stored proc RCE | Esecuzione via Java nel DB | manuale |
NoSQL & in-memory
| Tecnica | Come funziona | Tool / comando |
| MongoDB unauth | Accesso senza credenziali | mongo IP |
| MongoDB enum | Db, collezioni, dump | mongodump |
| NoSQL injection | Operatori per bypass/estrazione | nosqlmap |
| Redis unauth | Accesso senza password | redis-cli |
| Redis RCE (webshell) | Scrivi file via CONFIG SET | manuale |
| Redis RCE (module/SSH key) | Carica modulo o chiave SSH | manuale |
| Redis replication RCE | Master malevolo → carica modulo | redis-rogue-server |
| Memcached dump | Estrai dati in cache | memcstat |
| Elasticsearch unauth | Indici leggibili | curl :9200 |
| Elasticsearch RCE (CVE) | Groovy/old CVE | searchsploit |
| CouchDB RCE | CVE di privilege escalation | searchsploit |
| Cassandra enum | Keyspace e tabelle | cqlsh |
Altri DBMS
| Tecnica | Come funziona | Tool / comando |
| SQLite file analysis | DB su file: leggi tutto | sqlite3 file.db |
| SQLite deleted records | Recupera record cancellati | forensic tool |
| MS Access (.mdb) | Estrai tabelle/credenziali | mdb-tools |
| IBM DB2 enum | Istanze e privilegi | db2 CLI |
| Sybase/SAP ASE | xp_cmdshell equivalente | manuale |
| Firebird/Interbase | Default creds e file DB | manuale |
Post-accesso DB
| Tecnica | Come funziona | Tool / comando |
| Credential reuse | Password DB riusate per SSH/OS | manuale |
| Sensitive data dump | Estrai PII/credenziali | sqlmap --dump |
| Hash cracking | Rompi gli hash estratti | hashcat |
| Backup/exfil | Esfiltra il database | mysqldump |
| Persistence (trigger/job) | Backdoor via trigger o scheduled job | manuale |
| DBA → OS pivot | Dal DB al sistema operativo | manuale |