Home › Arsenale › Database

Arsenale · Attacchi ai Database

DBMS esposti o raggiunti via SQLi: enumerazione, credenziali, lettura file e RCE. Tutorial injection: SQL Injection.

Solo su DB tuoi o in scope.

MySQL / MariaDB

TecnicaCome funzionaTool / comando
Auth brute forcePassword deboli/root vuotahydra mysql
Version/enumVersione, db, utentiSELECT version()
File readLeggi file col privilegio FILELOAD_FILE()
File write / webshellScrivi file nella webrootINTO OUTFILE
UDF RCEUser Defined Function → comando OSraptor_udf
Hash dumpEstrai gli hash utenteSELECT user,password FROM mysql.user
Privilege enumCosa può fare l'utenteSHOW GRANTS
Trigger backdoorPersistenza via triggermanuale

MSSQL

TecnicaCome funzionaTool / comando
Auth brute / loginsa e password debolimssqlclient.py
xp_cmdshell RCEEsegui comandi OSEXEC xp_cmdshell
Enable xp_cmdshellRiattivalo via sp_configuresp_configure
Linked serversPivot su altri DB fidatiOPENQUERY
Impersonation (EXECUTE AS)Escalation a sysadminmanuale
UNC hash captureForza auth verso responderxp_dirtree
OLE automation RCEEsecuzione via sp_OACreatemanuale
CLR assembly RCECarica assembly .NETPowerUpSQL
Enum con PowerUpSQLScopri istanze e privilegiPowerUpSQL
Trustworthy DB abuseEscalation via db TRUSTWORTHYmanuale

PostgreSQL

TecnicaCome funzionaTool / comando
Auth brutePassword debolihydra postgres
COPY TO/FROM PROGRAMEsegui comandi OS (9.3+)COPY ... FROM PROGRAM
File read/writepg_read_file / lo_exportmanuale
Large object RCEScrivi librerie via LOmanuale
Privilege enumRuoli e permessi\du
Extension RCECarica estensione malevolamanuale

Oracle

TecnicaCome funzionaTool / comando
TNS/SID enumScopri SID e listenerodat · tnscmd
Default credentialsscott/tiger, systemliste
PL/SQL injectionEscalation via packagemanuale
File/OS via odatLettura file, RCEodat
Password hash extractionDump degli hashodat
Java stored proc RCEEsecuzione via Java nel DBmanuale

NoSQL & in-memory

TecnicaCome funzionaTool / comando
MongoDB unauthAccesso senza credenzialimongo IP
MongoDB enumDb, collezioni, dumpmongodump
NoSQL injectionOperatori per bypass/estrazionenosqlmap
Redis unauthAccesso senza passwordredis-cli
Redis RCE (webshell)Scrivi file via CONFIG SETmanuale
Redis RCE (module/SSH key)Carica modulo o chiave SSHmanuale
Redis replication RCEMaster malevolo → carica moduloredis-rogue-server
Memcached dumpEstrai dati in cachememcstat
Elasticsearch unauthIndici leggibilicurl :9200
Elasticsearch RCE (CVE)Groovy/old CVEsearchsploit
CouchDB RCECVE di privilege escalationsearchsploit
Cassandra enumKeyspace e tabellecqlsh

Altri DBMS

TecnicaCome funzionaTool / comando
SQLite file analysisDB su file: leggi tuttosqlite3 file.db
SQLite deleted recordsRecupera record cancellatiforensic tool
MS Access (.mdb)Estrai tabelle/credenzialimdb-tools
IBM DB2 enumIstanze e privilegidb2 CLI
Sybase/SAP ASExp_cmdshell equivalentemanuale
Firebird/InterbaseDefault creds e file DBmanuale

Post-accesso DB

TecnicaCome funzionaTool / comando
Credential reusePassword DB riusate per SSH/OSmanuale
Sensitive data dumpEstrai PII/credenzialisqlmap --dump
Hash crackingRompi gli hash estrattihashcat
Backup/exfilEsfiltra il databasemysqldump
Persistence (trigger/job)Backdoor via trigger o scheduled jobmanuale
DBA → OS pivotDal DB al sistema operativomanuale