A database server is reached as a network service, and once you can authenticate it is far more than a data store: the major engines can run operating-system commands, read and write files on the host, impersonate other database principals, and pivot across trust links to other servers. In a Windows estate the database service also runs as a privileged account and speaks NTLM, so it is a first-class foothold and lateral-movement target, not just a source of data.
This area organises attacks per engine, because the query language, privilege model, and command-execution primitives differ sharply between them.
What to reach for#
- Access and enumeration: get a login (default, weak, or captured), then map databases, roles, and the privileges you hold.
- Command execution: turn query access into code on the host.
- File access: read and write host files through the engine.
- Privilege escalation inside the engine: impersonation and ownership chains to reach administrative rights.
- Lateral movement: trust links between servers, and coercing the service account's authentication for relay.
Engines#
- MSSQL: Microsoft SQL Server, the richest and most AD-integrated target: xp_cmdshell, linked servers, impersonation, and coercion to NTLM relay.
- PostgreSQL: superuser command execution through COPY FROM PROGRAM and untrusted languages, plus file read and write.
- MySQL and MariaDB: file write to a webshell with INTO OUTFILE and OS command execution through a user-defined function.
- Oracle Database: TNS and SID enumeration, default accounts, and command execution through the scheduler, Java, and external tables.
- Redis: unauthenticated access and the file-write and module-load paths to code execution.
- MongoDB: unauthenticated exposure, enumeration, and server-side JavaScript where enabled.