COMMON ATTACK PATTERN ENUMERATION AND CLASSIFICATIONLive MITRE record

CAPEC-108

Command Line Execution through SQL Injection

An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Sometime later, an unscrupulous backend application (or could be part of the functionality of the same application) fetches the injected data stored in the database and uses this data as command line arguments without performing proper validation. The malicious data escapes that data plane by spawning new commands to be executed on the host.

Abstraction

Detailed

Typical severity

Very High

Likelihood of attack

Low

Understand the attack

What is this attack pattern?

An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Sometime later, an unscrupulous backend application (or could be part of the functionality of the same application) fetches the injected data stored in the database and uses this data as command line arguments without performing proper validation. The malicious data escapes that data plane by spawning new commands to be executed on the host.

Execution flow

How does the attack proceed, step by step?

1

Explore

Probe for SQL Injection vulnerability

The attacker injects SQL syntax into user-controllable data inputs to search unfiltered execution of the SQL syntax in a query.
2

Exploit

Achieve arbitrary command execution through SQL Injection with the MSSQL_xp_cmdshell directive

The attacker leverages a SQL Injection attack to inject shell code to be executed by leveraging the xp_cmdshell directive.

Inject malicious data in the database

Leverage SQL injection to inject data in the database that could later be used to achieve command injection if ever used as a command line argument

Trigger command line execution with injected arguments

The attacker causes execution of command line functionality which leverages previously injected database content as arguments.

Requirements

What does the attack require?

Prerequisites

  • The application does not properly validate data before storing in the database
  • Backend application implicitly trusts the data stored in the database
  • Malicious data is used on the backend as a command line argument

Skills required

  • High: The attacker most likely has to be familiar with the internal functionality of the system to launch this attack. Without that knowledge, there are not many feedback mechanisms to give an attacker the indication of how to perform command injection or whether the attack is succeeding.

Resources required

  • None: No specialized resources are required to execute this type of attack.

Impact

What does a successful attack lead to?

Modify Data

Affected scopes: Integrity

Read Data

Affected scopes: Confidentiality

Unreliable Execution

Affected scopes: Availability

Gain Privileges

Affected scopes: Confidentiality, Access Control, Authorization

Execute Unauthorized Commands

Affected scopes: Confidentiality, Integrity, Availability

Defence

How is it prevented and mitigated?

1
Disable MSSQL xp_cmdshell directive on the database
2
Properly validate the data (syntactically and semantically) before writing it to the database.
3
Do not implicitly trust the data stored in the database. Re-validate it prior to usage to make sure that it is safe to use in a given context (e.g. as a command line argument).

Real world

MITRE example instances

Example instance 1Detail
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function ( CVE-2006-6799) . Reference: https://www.cve.org/CVERecord?id= CVE-2006-6799
CAPEC-108: Command Line Execution through SQL Injection — DayBreach Saldırı Sözlüğü · DayBreach