# Secrets from master + msdb (restore into a local container, 2026-09-16)

## Source
- `master_sysbak_09162026.bak` (0.9 MB) — BACKUP DATABASE [master] WITH COMPRESSION, COPY_ONLY
- `msdb_sysbak_09162026.bak` (69.0 MB) — BACKUP DATABASE [msdb] WITH COMPRESSION, COPY_ONLY
- Both restored into the local container `mssql-irely` as `master_restore` / `msdb_restore`, analyzed offline, then the DBs and .bak files were deleted.

## master — SQL logins with password hashes

| Login | Type | Disabled | password_hash (hex) |
|---|---|---|---|
| **sa** | SQL_LOGIN | no | `0x02002686203F6F4C4FF020556F8D1B4ADA781BAF54A81E887773BD4D84670B94EDCF1B3831320B01EA57DA770EF77560C2906DA2D594A977CB2D90137437F99007A271B31913` |
| ##MS_PolicyEventProcessingLogin## | SQL_LOGIN | yes | `0x0200B67D2579A8E462817583965E46FA0EDFE91B928BAD828F8D15D9C346B277B386457F5AFA7B8EA2CB72B647C536B72AEE572BBF503EAEF80D66715C89FFFF478FEDE8D35E` |
| ##MS_PolicyTsqlExecutionLogin## | SQL_LOGIN | yes | `0x02007F2A730867159F42A84CBC98AF4C80E6966BCC4BCAF1F87DCF8C699A899B341FD1D8AEDE53F379C25180BF60C1A911189F16D252E5DA99846CED91078A92538EF2F9FDD4` |
| NT AUTHORITY\NETWORK SERVICE | WINDOWS_LOGIN | no | NULL (Windows auth) |
| NT AUTHORITY\SYSTEM | WINDOWS_LOGIN | no | NULL (Windows auth) |

### sa hash — details
Format: `0x0200` + salt (4 bytes `26862032`) + SHA2_512 hash (64 bytes).
hashcat mode: `1800` (mssql2012) — `0x0200{salt}{hash}`.
This is **production sa** — the hash may be weak (if the password = "irely486" or similar, brute-force is fast).

### sysadmin members
- **sa** (SQL_LOGIN, sid=0x01) — confirmed
- **irely** (SQL_LOGIN, sid=0xAD81F3A9C566B74482B1B20944BB118E, created 2024-05-12) — **7 roles**: sysadmin, securityadmin, serveradmin, setupadmin, diskadmin, dbcreator, bulkadmin
- **BUILTIN\Administrators** (WINDOWS_GROUP) — any local Windows administrator
- **NT AUTHORITY\NETWORK SERVICE** (WINDOWS_LOGIN) — IIS/SQL service account

### irely — complementary result (from the live server)
irely didn't make it into the master backup for the reason: its hash in sys.sql_logins is stored in the current master.mdf,
but a COPY_ONLY backup may not capture changes if the log isn't flushed, or the login was recreated
after the last checkpoint. The hash was obtained directly from the live server:
`0x0200113D5709B0F7580786701B5330210ED0DD521F624D16B81CAB0DC286D073757A87E3C1CE3C5368C4A48C36D9D85D243630F02F48B71FEC5FD08724D68E64A03B52413E45`
Format is the same: `0x0200` + salt (4B `113D5709`) + SHA2_512 hash (64B).
hashcat mode 1800. The password is already known from source (iRely486) — but the hash confirms it independently.

### Linked servers: NONE (0)
### Server credentials: NONE (0)
### Endpoints: only standard TSQL (TCP, Shared Memory, Named Pipes, VIA)
### Server permissions: CONNECT SQL → sa

## msdb — SQL Agent / Database Mail / Credentials

| Object | Count | Contents |
|---|---|---|
| sysjobs | 1 | `syspolicy_purge_history` (standard, MS-shipped) |
| sysjobsteps | 3 | Verify automation / Purge history / Erase phantom records (PowerShell) |
| **syscredentials** | **0** | no credentials |
| **sysproxies** | **0** | no proxies |
| **sysmail_account** | **0** | Database Mail not configured |
| **sysmail_server** | **0** | no SMTP |
| **sysoperators** | **0** | no operators (no alerts/email notifications) |
| sysalerts | 0 | no alerts |
| systargetservers | 0 | no multi-server mgmt |
| sysdbmaintplans | 1 | "All ad-hoc plans" (owner=sa, legacy placeholder) |
| syscachedcredentials | 0 | empty |

### Key conclusion
**msdb is empty in terms of secrets.** Their backup mechanism (Jenkins4_*.bak) is **NOT SQL Agent** but an external Jenkins agent. SQL Agent is only used for the standard `syspolicy_purge_history`. Database Mail isn't configured, credentials/proxies are absent. This means:
- Jenkins-agent creds are NOT stored in msdb → likely in Jenkins config (XML/credentials.xml) or in the system keyring
- No SMTP password → no email notifications at the SQL level
- Vulnerability: **BUILTIN\Administrators = sysadmin** — anyone who gets admin on the Windows host is automatically sysadmin on SQL (without a separate password)

## What's valuable
1. **sa password_hash** — target for hashcat mode 1800 (SHA2_512+salt).
2. **irely password_hash** — password already known (iRely486), but the hash is confirmed independently.
3. **BUILTIN\Administrators = sysadmin** — an attacker with Windows-admin = SQL-sysadmin (path via RDP/Windows exploit).
4. **irely — 7 roles** (sysadmin+securityadmin+serveradmin+setupadmin+diskadmin+dbcreator+bulkadmin) — nearly full control.
5. msdb is empty — Jenkins creds are stored in Jenkins config, not SQL.

## Cleanup
- `master_restore` and `msdb_restore` dropped from the container
- .bak files (master_sysbak.bak, msdb_sysbak.bak) deleted locally
- Temp .bak on the server already deleted (by script, GONE after upload)
- On ch12 remain: master_sysbak_09162026.bak, msdb_sysbak_09162026.bak (for your verification)
