The SQL Server Crypto Detour
ID: c213c7ab-3eca-5c2b-ae95-94ec219eb17c
STIX ID: report--c213c7ab-3eca-5c2b-ae95-94ec219eb17c
Feed Name: XPN InfoSec Blog
This blog post details SpecterOps' analysis and reverse engineering of SQL Server encryption used by ManageEngine ADSelfService Plus, showing that backups include the Database Master Key (DMK) material and that the product used an example/default DMK password (23987hxJ#KL95234nl0zBe). The author explains the SMK/DMK/DPAPI chain, describes methods to brute-force DMK thumbprints for ESKP (MD5, fast GPU cracking) and ESP2 (SHA-512 truncated, slower), and demonstrates how a compromised .bak file can be used to decrypt sensitive data (including Domain Admin credentials) from the database.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
