Umbra Wiki attack-pattern attack-pattern/CAPEC-108
Back to wiki

CAPEC-108 — Command Line Execution through SQL Injection

provenance: imported · CWE: CWE-20 CWE-74 CWE-78 CWE-89 CWE-114

CAPEC-108: Command Line Execution through SQL Injection

MITRE CAPEC attack pattern

Status Draft
Typical severity Very High
Likelihood of attack Low
Catalogue CAPEC 3.9 (2023-01-24)

Description

An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Sometime later, an unscrupulous backend application (or could be part of the functionality of the same application) fetches the injected data stored in the database and uses this data as command line arguments without performing proper validation. The malicious data escapes that data plane by spawning new commands to be executed on the host.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-20, CWE-74, CWE-78, CWE-89, CWE-114

Prerequisites

  • The application does not properly validate data before storing in the database
  • Backend application implicitly trusts the data stored in the database
  • Malicious data is used on the backend as a command line argument

Skills required

  • High: The attacker most likely has to be familiar with the internal functionality of the system to launch this attack. Without that knowledge, there are not many feedback mechanisms to give an attacker the indication of how to perform command injection or whether the attack is succeeding.

Consequences

  • Integrity: Modify Data
  • Confidentiality: Read Data
  • Availability: Unreliable Execution
  • Confidentiality, Access Control, Authorization: Gain Privileges
  • Confidentiality, Integrity, Availability: Execute Unauthorized Commands

Mitigations

  • Disable MSSQL xp_cmdshell directive on the database
  • Properly validate the data (syntactically and semantically) before writing it to the database.
  • Do not implicitly trust the data stored in the database. Re-validate it prior to usage to make sure that it is safe to use in a given context (e.g. as a command line argument).

Source