[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGnR57i6das5bbmbo7RN4M_VX2jT3RCmuwDW2hyu07pc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1117,"How can I extract database credentials from Veeam Backup & Replication during vulnerability analysis?","Extract credentials by first obtaining the database connection port from SQL Server Configuration Manager (e.g., for VEEAMSQL2016) and the database name from the configuration page or registry. Then use tools like DbSchema or PowerShell scripts (e.g., veeam-creds, but with updated OLEDB driver like MSOLEDBSQL19) to connect and query the VeeamBackup database for stored credential information. For full details, see the credential extraction section in the [Veeam Backup & Replication Vulnerability Debugging Environment Setup](\u002Fnews\u002Fveeam-backup-replication-vulnerability-debugging-environment-setup) article.","\u003Cp>Extract credentials by first obtaining the database connection port from SQL Server Configuration Manager (e.g., for VEEAMSQL2016) and the database name from the configuration page or registry. Then use tools like DbSchema or PowerShell scripts (e.g., veeam-creds, but with updated OLEDB driver like MSOLEDBSQL19) to connect and query the VeeamBackup database for stored credential information. For full details, see the credential extraction section in the [Veeam Backup &amp; Replication Vulnerability Debugging Environment Setup](\u002Fnews\u002Fveeam-backup-replication-vulnerability-debugging-environment-setup) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fveeam-backup-replication-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-extract-database-credentials-from-veeam-backup-replication-during-vuln-1777480641895","database credential extraction, VeeamBackup, SQL Server, PowerShell, veeam-creds, OLEDB driver",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},272,"Veeam Backup & Replication Vulnerability Debugging Environment Setup","veeam-backup-replication-vulnerability-debugging-environment-setup","Step-by-step guide to setting up Veeam Backup & Replication vulnerability debugging environment (CVE-2023-27532): env setup, debugging steps, credential extraction.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>Veeam Backup &amp; Replication Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article takes CVE-2023-27532 as an example to introduce the setup method of the Veeam Backup &amp; Replication vulnerability debugging environment.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>Environment Setup\u003C\u002Fp>\u003Cp>Debugging Environment Setup\u003C\u002Fp>\u003Cp>Database Credential Extraction\u003C\u002Fp>\u003Cp>Brief Analysis of CVE-2023-27532\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Software Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Installation Document: https:\u002F\u002Fhelpcenter.veeam.com\u002Farchive\u002Fbackup\u002F110\u002Fvsphere\u002Finstall_vbr.html\u003C\u002Fp>\u003Cp>Software Download Link: https:\u002F\u002Fwww.veeam.com\u002Fdownload-version.html\u003C\u002Fp>\u003Cp>License Application Link: https:\u002F\u002Fwww.veeam.com\u002Fsmb-vmware-hyper-v-essentials-download.html\u003C\u002Fp>\u003Cp>Download the ISO file; the License file obtained via email is required during installation.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Default Directory\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Installation Directory：C:\\\\Program Files\\\\Veeam\\\\\u003C\u002Fp>\u003Cp>Log Path：C:\\\\ProgramData\\\\Veeam\\\\Backup\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Default Ports\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Veeam.Backup.Service ports: 9392,9401(SSL)\u003C\u002Fp>\u003Cp>Veeam.Backup.ConfigurationService port: 9380\u003C\u002Fp>\u003Cp>Veeam.Backup.CatalogDataService port:9393\u003C\u002Fp>\u003Cp>Veeam.Backup.EnterpriseService port：9394\u003C\u002Fp>\u003Cp>Web UI ports:9080,9443(SSL)\u003C\u002Fp>\u003Cp>RESTful API ports:9399,9398(SSL)\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Debug Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Locate Process\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute Command：netstat -ano |findstr 9401\u003C\u002Fp>\u003Cp>Return Result：\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397695424_0_7437c9e42e.png\">\u003C\u002Fp>\u003Cp>Located process with pid 7132, process name is Veeam.Backup.Service.exe\u003C\u002Fp>\u003Cp>Use dnSpy to attach to the process Veeam.Backup.Service.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Debug Settings\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To view variable contents during the Debug process, the following files need to be created:\u003C\u002Fp>\u003Cp>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.Service.ini\u003C\u002Fp>\u003Cp>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.DBManager.ini\u003C\u002Fp>\u003Cp>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.ServiceLib.ini\u003C\u002Fp>\u003Cp>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.Interaction.MountService.ini\u003C\u002Fp>\u003Cp>Content is:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397700398_1_54d24d5f73.png\">\u003Cstrong>0x04 Database Credential Extraction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtain Database Connection Configuration\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Obtain Database Connection Port\u003C\u002Fp>\u003Cp>Open SQL Server 2016 Configuration Manager, select SQL Server Services, and you can see that the Process ID corresponding to SQL Server (VEEAMSQL2016) is 1756, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397703998_2_d4e12ac5b3.png\">Check the port corresponding to the process: netstat -ano|findstr 1756\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397709617_3_9233516c51.png\">\u003C\u002Fp>\u003Cp>Obtain the connection port 49720\u003C\u002Fp>\u003Cp>(2) Get the database name\u003C\u002Fp>\u003Cp>Method 1:\u003C\u002Fp>\u003Cp>Go to Configuration Database Connection Settings, on the page you can see the Database name is VeeamBackup and the authentication method is Windows Authentication, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397712492_4_9cf0afef7d.png\">\u003C\u002Fp>\u003Cp>Method 2:\u003C\u002Fp>\u003Cp>Read the registry key value: REG QUERY \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Veeam\\Veeam Backup and Replication\" \u002Fv SqlDatabaseName\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Database connection\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Use a GUI program\u003C\u002Fp>\u003Cp>Use DbSchema here\u003C\u002Fp>\u003Cp>Select SqlServer, configure as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397716345_5_fd0a203f32.png\">\u003C\u002Fp>\u003Cp>Successful connection as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397726172_6_984f61e546.png\">\u003C\u002Fp>\u003Cp>Select the database VeeamBackup.dbo, enter the database page, search for the keyword 'password' globally, and get the relevant query statement:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397731690_7_c32de47a8c.png\">After execution, obtain the credential information stored in the database, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397735477_8_8ef1d0bb47.png\">\u003C\u002Fp>\u003Cp>(2) Use Powershell\u003C\u002Fp>\u003Cp>Reference: https:\u002F\u002Fgithub.com\u002Fsadshade\u002Fveeam-creds\u003C\u002Fp>\u003Cp>When veeam-creds is tested on Veeam Backup and Replication 11 and higher versions, it will report an error with the prompt:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397740194_9_c0eece1ff7.png\">\u003C\u002Fp>\u003Cp>This is because sqloledb is used at https:\u002F\u002Fgithub.com\u002Fsadshade\u002Fveeam-creds\u002Fblob\u002Fmain\u002FVeeam-Get-Creds.ps1#L32, and the sqloledb on the current system has expired\u003C\u002Fp>\u003Cp>Here, you can choose to use MSOLEDBSQL or MSOLEDBSQL19 to resolve this issue\u003C\u002Fp>\u003Cp>PowerShell command to check if MSOLEDBSQL or MSOLEDBSQL19 is installed on the current system: (New-Object System.Data.OleDb.OleDbEnumerator).GetElements() | select SOURCES_NAME, SOURCES_DESCRIPTION\u003C\u002Fp>\u003Cp>Example of return result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397743926_10_cf01748ecb.png\">\u003C\u002Fp>\u003Cp>The above result shows that MSOLEDBSQL19 is installed on the current system, so you only need to replace sqloledb with MSOLEDBSQL19\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement: Method to install MSOLEDBSQL or MSOLEDBSQL19\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Download link: https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fsql\u002Fconnect\u002Foledb\u002Fdownload-oledb-driver-for-sql-server?source=recommendations&amp;view=sql-server-ver16\u003C\u002Fp>\u003Cp>Command line installation method: msiexec \u002Fi msoledbsql.msi \u002Fqn IACCEPTMSOLEDBSQLLICENSETERMS=YES\u003C\u002Fp>\u003Cp>Before installation, the minimum required version of Microsoft Visual C++ Redistributable is 14.34\u003C\u002Fp>\u003Cp>Simple method to check the version of Microsoft Visual C++ Redistributable:\u003C\u002Fp>\u003Cp>Obtained via folder name: dir \u002Fo:-d \\\"C:\\\\ProgramData\\\\Package Cache\\\"\u003C\u002Fp>\u003Cp>Example of return result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397749697_11_8fdc8847d9.png\">\u003C\u002Fp>\u003Cp>From this, we can see that the version of Microsoft Visual C++ Redistributable is 14.29.30037, so a higher version of Microsoft Visual C++ Redistributable needs to be installed. Download link: https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fcpp\u002Fwindows\u002Flatest-supported-vc-redist?view=msvc-170\u003C\u002Fp>\u003Cp>Both x86 and x64 versions need to be installed. The successful operation of veeam-creds is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397754634_12_e88957e20a.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x05 Brief Analysis of CVE-2023-27532\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Y4er published a POC for obtaining plaintext credentials by calling CredentialsDbScopeGetAllCreds: https:\u002F\u002Fy4er.com\u002Fposts\u002Fcve-2023-27532-veeam-backup-replication-leaked-credentials\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Credential Location\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The location corresponding to the plaintext credentials here is: Veeam Backup &amp; Replication Console -&gt; Manage Credentials. The default plaintext password is empty, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397758878_13_cd11942654.png\">The debug breakpoint location is Veeam.Backup.DBManager.dll -&gt; CCredentialsDbScope, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397763337_14_195f640722.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Data Parsing\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The final return result of the POC is serialized XML. After decrypting ParamValue with Base64, plaintext data can be seen, but the format is incorrect and there are garbled characters\u003C\u002Fp>\u003Cp>Here, you can call Veeam's built-in DLLs to deserialize the data and get the correct format\u003C\u002Fp>\u003Cp>Code example for formatted output string:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397767371_15_41f7823243.png\">\u003C\u002Fp>\u003Cp>Need to reference DLL files:\u003C\u002Fp>\u003Cp>Veeam.Backup.Common.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Configuration.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Interaction.MountService.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Logging.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Model.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Serialization.dll\u003C\u002Fp>\u003Cp>Veeam.TimeMachine.Tool.dll\u003C\u002Fp>\u003Cp>Compiled files need to be used in a local environment with Veeam installed; otherwise, an error message will be displayed:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397770747_16_53434b6614.png\">\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397773434_17_c832a04cdd.png\">\u003C\u002Fp>\u003Cp>An example of the program's successful execution result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fuploads\u002Fdocx_image_1769397774659_18_9a7ffcbd5e.png\">\u003Cstrong>0x06 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article takes CVE-2023-27532 as an example to introduce the relevant issues and solutions for setting up a Veeam Backup &amp; Replication vulnerability debugging environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>Veeam Backup &amp; Replication Vulnerability Debugging Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article takes CVE-2023-27532 as an example to introduce the setup method of the Veeam Backup &amp; Replication vulnerability debugging environment.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will cover the following content:\u003C\u002Fp>\u003Cp>Environment Setup\u003C\u002Fp>\u003Cp>Debugging Environment Setup\u003C\u002Fp>\u003Cp>Database Credential Extraction\u003C\u002Fp>\u003Cp>Brief Analysis of CVE-2023-27532\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Software Installation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Installation Document: https:\u002F\u002Fhelpcenter.veeam.com\u002Farchive\u002Fbackup\u002F110\u002Fvsphere\u002Finstall_vbr.html\u003C\u002Fp>\u003Cp>Software Download Link: https:\u002F\u002Fwww.veeam.com\u002Fdownload-version.html\u003C\u002Fp>\u003Cp>License Application Link: https:\u002F\u002Fwww.veeam.com\u002Fsmb-vmware-hyper-v-essentials-download.html\u003C\u002Fp>\u003Cp>Download the ISO file; the License file obtained via email is required during installation.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Default Directory\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Installation Directory：C:\\\\Program Files\\\\Veeam\\\\\u003C\u002Fp>\u003Cp>Log Path：C:\\\\ProgramData\\\\Veeam\\\\Backup\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Default Ports\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Veeam.Backup.Service ports: 9392,9401(SSL)\u003C\u002Fp>\u003Cp>Veeam.Backup.ConfigurationService port: 9380\u003C\u002Fp>\u003Cp>Veeam.Backup.CatalogDataService port:9393\u003C\u002Fp>\u003Cp>Veeam.Backup.EnterpriseService port：9394\u003C\u002Fp>\u003Cp>Web UI ports:9080,9443(SSL)\u003C\u002Fp>\u003Cp>RESTful API ports:9399,9398(SSL)\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Debug Environment Setup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Locate Process\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute Command：netstat -ano |findstr 9401\u003C\u002Fp>\u003Cp>Return Result：\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397695424_0_7437c9e42e-1.png\">\u003C\u002Fp>\u003Cp>Located process with pid 7132, process name is Veeam.Backup.Service.exe\u003C\u002Fp>\u003Cp>Use dnSpy to attach to the process Veeam.Backup.Service.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Debug Settings\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To view variable contents during the Debug process, the following files need to be created:\u003C\u002Fp>\u003Cp>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.Service.ini\u003C\u002Fp>\u003Cp>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.DBManager.ini\u003C\u002Fp>\u003Cp>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.ServiceLib.ini\u003C\u002Fp>\u003Cp>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.Interaction.MountService.ini\u003C\u002Fp>\u003Cp>Content is:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397700398_1_54d24d5f73-1.png\">\u003Cstrong>0x04 Database Credential Extraction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtain Database Connection Configuration\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Obtain Database Connection Port\u003C\u002Fp>\u003Cp>Open SQL Server 2016 Configuration Manager, select SQL Server Services, and you can see that the Process ID corresponding to SQL Server (VEEAMSQL2016) is 1756, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397703998_2_d4e12ac5b3-1.png\">Check the port corresponding to the process: netstat -ano|findstr 1756\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397709617_3_9233516c51-1.png\">\u003C\u002Fp>\u003Cp>Obtain the connection port 49720\u003C\u002Fp>\u003Cp>(2) Get the database name\u003C\u002Fp>\u003Cp>Method 1:\u003C\u002Fp>\u003Cp>Go to Configuration Database Connection Settings, on the page you can see the Database name is VeeamBackup and the authentication method is Windows Authentication, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397712492_4_9cf0afef7d-1.png\">\u003C\u002Fp>\u003Cp>Method 2:\u003C\u002Fp>\u003Cp>Read the registry key value: REG QUERY \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Veeam\\Veeam Backup and Replication\" \u002Fv SqlDatabaseName\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Database connection\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) Use a GUI program\u003C\u002Fp>\u003Cp>Use DbSchema here\u003C\u002Fp>\u003Cp>Select SqlServer, configure as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397716345_5_fd0a203f32-1.png\">\u003C\u002Fp>\u003Cp>Successful connection as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397726172_6_984f61e546-1.png\">\u003C\u002Fp>\u003Cp>Select the database VeeamBackup.dbo, enter the database page, search for the keyword 'password' globally, and get the relevant query statement:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397731690_7_c32de47a8c-1.png\">After execution, obtain the credential information stored in the database, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397735477_8_8ef1d0bb47-1.png\">\u003C\u002Fp>\u003Cp>(2) Use Powershell\u003C\u002Fp>\u003Cp>Reference: https:\u002F\u002Fgithub.com\u002Fsadshade\u002Fveeam-creds\u003C\u002Fp>\u003Cp>When veeam-creds is tested on Veeam Backup and Replication 11 and higher versions, it will report an error with the prompt:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397740194_9_c0eece1ff7-1.png\">\u003C\u002Fp>\u003Cp>This is because sqloledb is used at https:\u002F\u002Fgithub.com\u002Fsadshade\u002Fveeam-creds\u002Fblob\u002Fmain\u002FVeeam-Get-Creds.ps1#L32, and the sqloledb on the current system has expired\u003C\u002Fp>\u003Cp>Here, you can choose to use MSOLEDBSQL or MSOLEDBSQL19 to resolve this issue\u003C\u002Fp>\u003Cp>PowerShell command to check if MSOLEDBSQL or MSOLEDBSQL19 is installed on the current system: (New-Object System.Data.OleDb.OleDbEnumerator).GetElements() | select SOURCES_NAME, SOURCES_DESCRIPTION\u003C\u002Fp>\u003Cp>Example of return result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397743926_10_cf01748ecb-1.png\">\u003C\u002Fp>\u003Cp>The above result shows that MSOLEDBSQL19 is installed on the current system, so you only need to replace sqloledb with MSOLEDBSQL19\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement: Method to install MSOLEDBSQL or MSOLEDBSQL19\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Download link: https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fsql\u002Fconnect\u002Foledb\u002Fdownload-oledb-driver-for-sql-server?source=recommendations&amp;view=sql-server-ver16\u003C\u002Fp>\u003Cp>Command line installation method: msiexec \u002Fi msoledbsql.msi \u002Fqn IACCEPTMSOLEDBSQLLICENSETERMS=YES\u003C\u002Fp>\u003Cp>Before installation, the minimum required version of Microsoft Visual C++ Redistributable is 14.34\u003C\u002Fp>\u003Cp>Simple method to check the version of Microsoft Visual C++ Redistributable:\u003C\u002Fp>\u003Cp>Obtained via folder name: dir \u002Fo:-d \\\"C:\\\\ProgramData\\\\Package Cache\\\"\u003C\u002Fp>\u003Cp>Example of return result:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397749697_11_8fdc8847d9-1.png\">\u003C\u002Fp>\u003Cp>From this, we can see that the version of Microsoft Visual C++ Redistributable is 14.29.30037, so a higher version of Microsoft Visual C++ Redistributable needs to be installed. Download link: https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fcpp\u002Fwindows\u002Flatest-supported-vc-redist?view=msvc-170\u003C\u002Fp>\u003Cp>Both x86 and x64 versions need to be installed. The successful operation of veeam-creds is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397754634_12_e88957e20a-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x05 Brief Analysis of CVE-2023-27532\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Y4er published a POC for obtaining plaintext credentials by calling CredentialsDbScopeGetAllCreds: https:\u002F\u002Fy4er.com\u002Fposts\u002Fcve-2023-27532-veeam-backup-replication-leaked-credentials\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Credential Location\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The location corresponding to the plaintext credentials here is: Veeam Backup &amp; Replication Console -&gt; Manage Credentials. The default plaintext password is empty, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397758878_13_cd11942654-1.png\">The debug breakpoint location is Veeam.Backup.DBManager.dll -&gt; CCredentialsDbScope, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397763337_14_195f640722-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Data Parsing\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The final return result of the POC is serialized XML. After decrypting ParamValue with Base64, plaintext data can be seen, but the format is incorrect and there are garbled characters\u003C\u002Fp>\u003Cp>Here, you can call Veeam's built-in DLLs to deserialize the data and get the correct format\u003C\u002Fp>\u003Cp>Code example for formatted output string:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397767371_15_41f7823243-1.png\">\u003C\u002Fp>\u003Cp>Need to reference DLL files:\u003C\u002Fp>\u003Cp>Veeam.Backup.Common.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Configuration.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Interaction.MountService.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Logging.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Model.dll\u003C\u002Fp>\u003Cp>Veeam.Backup.Serialization.dll\u003C\u002Fp>\u003Cp>Veeam.TimeMachine.Tool.dll\u003C\u002Fp>\u003Cp>Compiled files need to be used in a local environment with Veeam installed; otherwise, an error message will be displayed:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397770747_16_53434b6614-1.png\">\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397773434_17_c832a04cdd-1.png\">\u003C\u002Fp>\u003Cp>An example of the program's successful execution result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】Veeam Backup &amp; Replication漏洞调试环境搭建\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397774659_18_9a7ffcbd5e-1.png\">\u003Cstrong>0x06 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article takes CVE-2023-27532 as an example to introduce the relevant issues and solutions for setting up a Veeam Backup &amp; Replication vulnerability debugging environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",147,"Onedaysec",4,"published","2026-02-02T07:25:19.984Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Veeam Backup & Replication Vulnerability Debug Env Setup (CVE-2023-27532)","Veeam Backup & Replication, vulnerability debugging environment setup, CVE-2023-27532, Veeam service ports, database credential extraction, dnSpy debugging, Veeam.Backup.Service.exe",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],1120,1119,1118,1116,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.453Z","2026-07-23T16:02:32.966Z","draft","2026-07-23T16:16:46.673Z"]