Files
nuclei-templates/javascript/enumeration/pgsql/pgsql-list-database.yaml
2024-06-14 16:56:22 +02:00

53 lines
1.7 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
id: pgsql-list-database
info:
name: PostgreSQL List Database
author: pussycat0x
severity: high
description: |
A single Postgres server process can manage multiple databases at the same time. Each database is stored as a separate set of files in its own directory within the servers data directory.
reference:
- https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/PostgreSQL%20Injection.md#postgresql-list-password-hashes
- https://launchbylunch.com/posts/2024/Jan/16/postgres-password-encryption/#postgresql-password-encryption-scram-sha-256
metadata:
verified: true
max-request: 8
shodan-query: "product:\"PostgreSQL\""
tags: js,network,postgresql,authenticated,enum
javascript:
- pre-condition: |
var m = require("nuclei/postgres");
var c = m.PGClient();
c.IsPostgres(Host, Port);
code: |
const postgres = require('nuclei/postgres');
const client = new postgres.PGClient;
connected = client.ExecuteQuery(Host, Port, User, Pass, Db, "SELECT datname FROM pg_database");
Export(connected);
args:
Host: "{{Host}}"
Port: 5432
User: "{{usernames}}"
Pass: "{{password}}"
Db: "{{database}}"
payloads:
usernames:
- postgres
- admin
password:
- postgres
-
- 123
- amber
database:
- postgres
attack: clusterbomb
extractors:
- type: json
json:
- '.Rows[].datname'
# digest: 4a0a004730450220194757a2f6a4644cd24e525bc9102446438aa7f44afa2ea39d6b1532d3c9faa0022100b086fea6b01fcfdb0f16c98359bf3ed9e70a0572cc0c17ece4e444c9ca7b0019:922c64590222798bb761d5b6d8e72950