database.nix (1776B)
1 # modules/features/pentest/database.nix — clients for the databases you find 2 # listening, once credentials turn up. 3 # Off by default. `daemon.pentest.database.enable = true;` 4 # 5 # Clients only, and that is a deliberate constraint rather than a preference: 6 # 7 # * No `postgresql`. The bloodhound category runs a postgres SERVICE, and 8 # NixOS puts that service's package (17.x) into environment.systemPackages 9 # itself. Adding `pkgs.postgresql` (currently 18.x) would give two store 10 # paths owning bin/psql, which is a profile collision that stops the whole 11 # system building. So `psql` comes from the bloodhound category, and this 12 # one brings `pgcli`, which is a better interactive client anyway. 13 # * `mariadb.client`, not `mariadb` — the latter is the server, and installs 14 # mariadbd and its data-directory tooling for nothing. 15 # 16 # sqlmap is in web.nix: it is an injection tool, not a database client. 17 { lib, ... }: 18 (import ./_sets.nix { inherit lib; }) { 19 name = "database"; 20 description = "mysql, postgres, mssql, redis and mongo clients"; 21 default = false; 22 23 packages = pkgs: with pkgs; [ 24 mariadb.client # `mysql`, `mariadb`, `mysqldump` — MySQL and MariaDB 25 mycli # the same with completion and history 26 27 pgcli # postgres; `psql` itself comes with the bloodhound category 28 29 # MSSQL, which is what an AD estate actually runs 30 freetds # `tsql` — the one that works with just a host and port 31 sqsh 32 sqlcmd # Microsoft's own client 33 34 redis # `redis-cli` 35 mongosh 36 37 usql # one client for all of the above, by URL 38 ]; 39 40 expectedBins = [ 41 "mysql" "mariadb" "mysqldump" "mycli" 42 "pgcli" 43 "tsql" "bsqldb" "sqsh" "sqlcmd" 44 "redis-cli" "mongosh" 45 "usql" 46 ]; 47 48 smokeBins = [ "mycli" "pgcli" "usql" ]; 49 }