NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

database.nix (1776B)


      1 # modules/features/pentest/database.nix — clients for the databases you find
      2 # listening, once credentials turn up.
      3 # Off by default. `daemon.pentest.database.enable = true;`
      4 #
      5 # Clients only, and that is a deliberate constraint rather than a preference:
      6 #
      7 #  * No `postgresql`. The bloodhound category runs a postgres SERVICE, and
      8 #    NixOS puts that service's package (17.x) into environment.systemPackages
      9 #    itself. Adding `pkgs.postgresql` (currently 18.x) would give two store
     10 #    paths owning bin/psql, which is a profile collision that stops the whole
     11 #    system building. So `psql` comes from the bloodhound category, and this
     12 #    one brings `pgcli`, which is a better interactive client anyway.
     13 #  * `mariadb.client`, not `mariadb` — the latter is the server, and installs
     14 #    mariadbd and its data-directory tooling for nothing.
     15 #
     16 # sqlmap is in web.nix: it is an injection tool, not a database client.
     17 { lib, ... }:
     18 (import ./_sets.nix { inherit lib; }) {
     19   name = "database";
     20   description = "mysql, postgres, mssql, redis and mongo clients";
     21   default = false;
     22 
     23   packages = pkgs: with pkgs; [
     24     mariadb.client # `mysql`, `mariadb`, `mysqldump` — MySQL and MariaDB
     25     mycli # the same with completion and history
     26 
     27     pgcli # postgres; `psql` itself comes with the bloodhound category
     28 
     29     # MSSQL, which is what an AD estate actually runs
     30     freetds # `tsql` — the one that works with just a host and port
     31     sqsh
     32     sqlcmd # Microsoft's own client
     33 
     34     redis # `redis-cli`
     35     mongosh
     36 
     37     usql # one client for all of the above, by URL
     38   ];
     39 
     40   expectedBins = [
     41     "mysql" "mariadb" "mysqldump" "mycli"
     42     "pgcli"
     43     "tsql" "bsqldb" "sqsh" "sqlcmd"
     44     "redis-cli" "mongosh"
     45     "usql"
     46   ];
     47 
     48   smokeBins = [ "mycli" "pgcli" "usql" ];
     49 }