PostgreSQL

PostgreSQL (port 5432) is a frequent target because, as a superuser, it will run operating-system commands and read or write arbitrary files on the host, all through documented features. Even as a non-superuser there are file and function primitives worth reaching for, and several well-known paths promote an ordinary role to superuser.

What to reach for#

  • Access: default and weak credentials, trust authentication, and reaching a login.
  • Command execution: COPY ... FROM PROGRAM, untrusted languages (plpythonu, plperlu), and C extensions.
  • File access: COPY, large objects, and pg_read_file to read and write host files.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more