MySQL and MariaDB

MySQL and its fork MariaDB (port 3306) give two main offensive primitives once you authenticate: file read and write through LOAD_FILE and INTO OUTFILE (gated by the FILE privilege and secure_file_priv), and operating-system command execution through a user-defined function. The file write alone is often enough, dropping a webshell under a served directory.

What to reach for#

  • Command execution: a user-defined function (lib_mysqludf_sys) that runs OS commands as the service account.
  • File access: INTO OUTFILE to write a webshell, LOAD_FILE to read host files.

Getting a session#

bash
# default/weak credentials, commonly root with no or a weak password
mysql -h <target> -u root -p
hydra -L users.txt -P passwords.txt <target> mysql

References#

Cookie Consent

We use cookies to enhance your experience. Learn more