Database servers

A database server is reached as a network service, and once you can authenticate it is far more than a data store: the major engines can run operating-system commands, read and write files on the host, impersonate other database principals, and pivot across trust links to other servers. In a Windows estate the database service also runs as a privileged account and speaks NTLM, so it is a first-class foothold and lateral-movement target, not just a source of data.

This area organises attacks per engine, because the query language, privilege model, and command-execution primitives differ sharply between them.

What to reach for#

  • Access and enumeration: get a login (default, weak, or captured), then map databases, roles, and the privileges you hold.
  • Command execution: turn query access into code on the host.
  • File access: read and write host files through the engine.
  • Privilege escalation inside the engine: impersonation and ownership chains to reach administrative rights.
  • Lateral movement: trust links between servers, and coercing the service account's authentication for relay.

Engines#

  • MSSQL: Microsoft SQL Server, the richest and most AD-integrated target: xp_cmdshell, linked servers, impersonation, and coercion to NTLM relay.
  • PostgreSQL: superuser command execution through COPY FROM PROGRAM and untrusted languages, plus file read and write.
  • MySQL and MariaDB: file write to a webshell with INTO OUTFILE and OS command execution through a user-defined function.
  • Oracle Database: TNS and SID enumeration, default accounts, and command execution through the scheduler, Java, and external tables.
  • Redis: unauthenticated access and the file-write and module-load paths to code execution.
  • MongoDB: unauthenticated exposure, enumeration, and server-side JavaScript where enabled.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more