MySQL and its fork MariaDB (port 3306) give two main offensive primitives once you authenticate: file read and write through LOAD_FILE and INTO OUTFILE (gated by the FILE privilege and secure_file_priv), and operating-system command execution through a user-defined function. The file write alone is often enough, dropping a webshell under a served directory.
What to reach for#
- Command execution: a user-defined function (
lib_mysqludf_sys) that runs OS commands as the service account. - File access:
INTO OUTFILEto write a webshell,LOAD_FILEto read host files.
Getting a session#
# default/weak credentials, commonly root with no or a weak password
mysql -h <target> -u root -p
hydra -L users.txt -P passwords.txt <target> mysql