dblink-lo-import-data-exfiltration.md (1422B)
1 --- 2 title: "PostgreSQL dblink and loimport Data Exfiltration" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/sql-injection/postgresql-injection/dblink-lo_import-data-exfiltration.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/sql-injection/postgresql-injection/dblink-lo_import-data-exfiltration.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # PostgreSQL `dblink` and `lo_import` Data Exfiltration 14 15 In the documented challenge, PostgreSQL's `lo_import` function loads a server-side file as a large object and returns its object identifier (OID). When direct access to the imported object's contents is unavailable, the OID is embedded in a `dblink_connect` connection string and sent to an attacker-controlled PostgreSQL endpoint as an out-of-band exfiltration channel. This technique requires the relevant function privileges, the `dblink` extension, and outbound network access from the database server.<sup>[[1]](#references)</sup> 16 17 The complete challenge solution also explains how to validate each prerequisite and capture the resulting connection.<sup>[[1]](#references)</sup> 18 19 ## References 20 21 - [1] [PDKT-Team - FBCTF 2019 hr_admin_module writeup](https://github.com/PDKT-Team/ctf/blob/master/fbctf2019/hr-admin-module/README.md)