[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fK_OX-iYAk5f5TYy86doEp9IuvKBnrvuNMjCxcGsHrM0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},191,"What are the steps to extract database credentials from Veeam Backup & Replication, and how do I handle SSL errors in PowerShell?","First, obtain the database port via SQL Server Configuration Manager (e.g., PID 1756 mapped to port 49720) and the database name from registry or configuration (e.g., `VeeamBackup`). Then connect using DbSchema or PowerShell. For PowerShell, if using `veeam-creds`, replace the deprecated `sqloledb` provider with `MSOLEDBSQL` or `MSOLEDBSQL19` to avoid SSL errors. Ensure the latest Microsoft Visual C++ Redistributable is installed. The full method is covered in the [Setting Up Veeam Backup & Replication Vulnerability Debugging Environment](\u002Fnews\u002Fsetting-up-veeam-backup-replication-vulnerability-debugging-environment) article.","\u003Cp>First, obtain the database port via SQL Server Configuration Manager (e.g., PID 1756 mapped to port 49720) and the database name from registry or configuration (e.g., `VeeamBackup`). Then connect using DbSchema or PowerShell. For PowerShell, if using `veeam-creds`, replace the deprecated `sqloledb` provider with `MSOLEDBSQL` or `MSOLEDBSQL19` to avoid SSL errors. Ensure the latest Microsoft Visual C++ Redistributable is installed. The full method is covered in the [Setting Up Veeam Backup &amp; Replication Vulnerability Debugging Environment](\u002Fnews\u002Fsetting-up-veeam-backup-replication-vulnerability-debugging-environment) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsetting-up-veeam-backup-replication-vulnerability-debugging-environment\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-steps-to-extract-database-credentials-from-veeam-backup-replication-1777484874304","database credential extraction, VeeamBackup, PowerShell, MSOLEDBSQL, SSL error, CVE-2023-27532",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},50,"Setting Up Veeam Backup & Replication Vulnerability Debugging Environment","setting-up-veeam-backup-replication-vulnerability-debugging-environment","Learn to set up a Veeam Backup & Replication debugging environment, extract database credentials, and analyze CVE-2023-27532 vulnerability.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses CVE-2023-27532 as an example to introduce the method for setting up a Veeam Backup &amp; Replication vulnerability debugging environment.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Debugging Environment Setup\u003C\u002Fli>\u003Cli>Database Credential Extraction\u003C\u002Fli>\u003Cli>Brief Analysis of CVE-2023-27532\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Software Installation\u003C\u002Fh3>\u003Cp>Installation Documentation: https:\u002F\u002Fhelpcenter.veeam.com\u002Farchive\u002Fbackup\u002F110\u002Fvsphere\u002Finstall_vbr.html\u003C\u002Fp>\u003Cp>Software download address: https:\u002F\u002Fwww.veeam.com\u002Fdownload-version.html\u003C\u002Fp>\u003Cp>License application address: https:\u002F\u002Fwww.veeam.com\u002Fsmb-vmware-hyper-v-essentials-download.html\u003C\u002Fp>\u003Cp>Download the ISO file; the license file obtained via email is required during installation.\u003C\u002Fp>\u003Ch3>2. Default directories\u003C\u002Fh3>\u003Cp>Installation directory: C:\\Program Files\\Veeam\\\u003C\u002Fp>\u003Cp>Log path: C:\\ProgramData\\Veeam\\Backup\u003C\u002Fp>\u003Ch3>3. Default ports\u003C\u002Fh3>\u003Cul>\u003Cli>Veeam.Backup.Service ports: 9392, 9401 (SSL)\u003C\u002Fli>\u003Cli>Veeam.Backup.ConfigurationService port: 9380\u003C\u002Fli>\u003Cli>Veeam.Backup.CatalogDataService port: 9393\u003C\u002Fli>\u003Cli>Veeam.Backup.EnterpriseService port: 9394\u003C\u002Fli>\u003Cli>Web UI ports: 9080, 9443 (SSL)\u003C\u002Fli>\u003Cli>RESTful API ports: 9399, 9398 (SSL)\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Debug environment setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Locate Process\u003C\u002Fh3>\u003Cp>Execute command: netstat -ano | findstr 9401\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>TCP    0.0.0.0:9401           0.0.0.0:0              LISTENING       7132\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Located process PID is 7132, process name is Veeam.Backup.Service.exe\u003C\u002Fp>\u003Cp>Use dnSpy to attach to process Veeam.Backup.Service.exe\u003C\u002Fp>\u003Ch3>2. Debug Settings\u003C\u002Fh3>\u003Cp>To view variable contents during debugging, create the following files:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.Service.ini\u003C\u002Fli>\u003Cli>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.DBManager.ini\u003C\u002Fli>\u003Cli>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.ServiceLib.ini\u003C\u002Fli>\u003Cli>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.Interaction.MountService.ini\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Content is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[.NET Framework Debugging Control]\u003Cbr>Generate TrackingInfo=1\u003Cbr>AllowOptimize=0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart Service\u003C\u002Fp>\u003Ch2>0x04 Database Credential Extraction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain Database Connection Configuration\u003C\u002Fh3>\u003Ch4>(1) Obtain Database Connection Port\u003C\u002Fh4>\u003Cp>Open SQL Server 2016 Configuration Manager, select SQL Server Services, you can see that the Process ID corresponding to SQL Server (VEEAMSQL2016) is 1756, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019800797_0_78672cdc73.png\">\u003C\u002Fp>\u003Cp>Check the port corresponding to the process: netstat -ano|findstr 1756\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>  TCP    0.0.0.0:49720          0.0.0.0:0              LISTENING       1756\u003Cbr>  TCP    [::]:49720             [::]:0                 LISTENING       1756\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain connection port 49720\u003C\u002Fp>\u003Ch4>(2) Obtain Database Name\u003C\u002Fh4>\u003Cp>Method 1:\u003C\u002Fp>\u003Cp>Enter the Configuration Database Connection Settings page, where you can see the Database name as VeeamBackup and the authentication method as Windows Authentication, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019815475_1_d54e265606.png\">\u003C\u002Fp>\u003Cp>Method 2:\u003C\u002Fp>\u003Cp>Read the registry key value: REG QUERY \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Veeam\\Veeam Backup and Replication\" \u002Fv SqlDatabaseName\u003C\u002Fp>\u003Ch3>2. Database Connection\u003C\u002Fh3>\u003Ch4>(1) Using the Interface Program\u003C\u002Fh4>\u003Cp>Here, DbSchema is used.\u003C\u002Fp>\u003Cp>Select SqlServer and configure as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019826343_2_5d2d1e3429.png\">\u003C\u002Fp>\u003Cp>Successfully connected as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019839167_3_24d4e9583b.png\">\u003C\u002Fp>\u003Cp>Select the database VeeamBackup.dbo, enter the database page, and globally search for the keyword 'password' to obtain the relevant query statement:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT\u003Cbr>\tid, user_name, password, usn, description, visible, change_time_utc\u003Cbr>FROM\u003Cbr>\tVeeamBackup.dbo.Credentials s;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, obtain the credential information stored in the database, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019860608_4_9ab8c7a766.png\">\u003C\u002Fp>\u003Ch4>(2) Using Powershell\u003C\u002Fh4>\u003Cp>Reference: https:\u002F\u002Fgithub.com\u002Fsadshade\u002Fveeam-creds\u003C\u002Fp>\u003Cp>veeam-creds will report an error when tested on Veeam Backup and Replication 11 and later versions, with the prompt:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Exception calling \"Fill\" with \"1\" argument(s): \"[DBNETLIB][ConnectionOpen (SECDoClientHandshake()).]SSL Security error.\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This is because https:\u002F\u002Fgithub.com\u002Fsadshade\u002Fveeam-creds\u002Fblob\u002Fmain\u002FVeeam-Get-Creds.ps1#L32 uses sqloledb, and the sqloledb on the current system has expired\u003C\u002Fp>\u003Cp>Here you can choose to use MSOLEDBSQL or MSOLEDBSQL19 to resolve the issue\u003C\u002Fp>\u003Cp>PowerShell command to check if MSOLEDBSQL or MSOLEDBSQL19 is installed on the current system: (New-Object System.Data.OleDb.OleDbEnumerator).GetElements() | select SOURCES_NAME, SOURCES_DESCRIPTION\u003C\u002Fp>\u003Cp>Example of returned results:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SOURCES_NAME               SOURCES_DESCRIPTION\u003Cbr>------------               -------------------\u003Cbr>SQLOLEDB                   Microsoft OLE DB Provider for SQL Server\u003Cbr>MSOLEDBSQL19 Enumerator    Microsoft OLE DB Driver 19 for SQL Server Enumerator\u003Cbr>MSDataShape                MSDataShape\u003Cbr>SQLNCLI11                  SQL Server Native Client 11.0\u003Cbr>ADsDSOObject               OLE DB Provider for Microsoft Directory Services\u003Cbr>SQLNCLIRDA11               SQL Server Native Client RDA 11.0\u003Cbr>SQLNCLI11 Enumerator       SQL Server Native Client 11.0 Enumerator\u003Cbr>Windows Search Data Source Microsoft OLE DB Provider for Search\u003Cbr>SQLNCLIRDA11 Enumerator    SQL Server Native Client RDA 11.0 Enumerator\u003Cbr>SSISOLEDB                  OLE DB Provider for SQL Server Integration Services\u003Cbr>MSDASQL                    Microsoft OLE DB Provider for ODBC Drivers\u003Cbr>MSDASQL Enumerator         Microsoft OLE DB Enumerator for ODBC Drivers\u003Cbr>SQLOLEDB Enumerator        Microsoft OLE DB Enumerator for SQL Server\u003Cbr>MSDAOSP                    Microsoft OLE DB Simple Provider\u003Cbr>MSOLEDBSQL19               Microsoft OLE DB Driver 19 for SQL Server\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The above results show that MSOLEDBSQL19 is installed on the current system, so simply replace sqloledb with MSOLEDBSQL19.\u003C\u002Fp>\u003Ch4>Note: Method for installing MSOLEDBSQL or MSOLEDBSQL19.\u003C\u002Fh4>\u003Cp>Download address: https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fsql\u002Fconnect\u002Foledb\u002Fdownload-oledb-driver-for-sql-server?source=recommendations&amp;view=sql-server-ver16\u003C\u002Fp>\u003Cp>Command line installation method: msiexec \u002Fi msoledbsql.msi \u002Fqn IACCEPTMSOLEDBSQLLICENSETERMS=YES\u003C\u002Fp>\u003Cp>Microsoft Visual C++ Redistributable version must be at least 14.34 before installation\u003C\u002Fp>\u003Cp>Simple method to check Microsoft Visual C++ Redistributable version:\u003C\u002Fp>\u003Cp>Obtain via folder name: dir \u002Fo:-d \"C:\\ProgramData\\Package Cache\"\u003C\u002Fp>\u003Cp>Example return results:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{88a5e14d-0f76-42fd-a259-a53b8fde6c73}\u003Cbr>{7F2142C4-0C90-4792-89BF-5DF5E2306E59}v24.64.30112\u003Cbr>{FE134959-3504-4B60-9642-0FBBAF76B779}v24.64.30112\u003Cbr>{DF700CFE-0603-47E1-A45D-3369AD751E7E}v24.64.30112\u003Cbr>{4b6a8b46-ac89-45e8-8871-0be420bf9fa0}\u003Cbr>{529D20E8-132A-4F1A-A25F-9211B8C943AC}v14.29.30037\u003Cbr>{C874FB5A-1C85-460A-A4A9-CBCC3FAE7880}v14.29.30037\u003Cbr>{4b2f3795-f407-415e-88d5-8c8ab322909d}\u003Cbr>{C9DE51F8-7846-4621-815D-E8AFD3E3C0FF}v14.20.27508\u003Cbr>{B96F6FA1-530F-42F1-9F71-33C583716340}v14.20.27508\u003Cbr>{8c3f057e-d6a6-4338-ac6a-f1c795a6577b}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>From this, it can be concluded that the Microsoft Visual C++ Redistributable version is 14.29.30037. A higher version of Microsoft Visual C++ Redistributable needs to be installed. Download link: https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fcpp\u002Fwindows\u002Flatest-supported-vc-redist?view=msvc-170\u003C\u002Fp>\u003Cp>Both x86 and x64 need to be installed. veeam-creds runs successfully as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019866476_5_60307851d1.png\">\u003C\u002Fp>\u003Ch2>0x05 Brief Analysis of CVE-2023-27532\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Y4er published a POC that calls CredentialsDbScopeGetAllCreds to obtain plaintext credentials: https:\u002F\u002Fy4er.com\u002Fposts\u002Fcve-2023-27532-veeam-backup-replication-leaked-credentials\u002F\u003C\u002Fp>\u003Ch3>1. Credential Location\u003C\u002Fh3>\u003Cp>The plaintext credentials here correspond to the location: Veeam Backup &amp; Replication Console -&gt; Manage Credentials. The default plaintext password is empty, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870169_6_2e29fd8646.png\">\u003C\u002Fp>\u003Cp>The debugging breakpoint location is Veeam.Backup.DBManager.dll -&gt; CCredentialsDbScope, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019875098_7_5cb236a3d9.png\">\u003C\u002Fp>\u003Ch3>2. Data Parsing\u003C\u002Fh3>\u003Cp>The final return result of the POC is serialized XML. After Base64 decoding ParamValue, plaintext data can be seen, but the format is incorrect and contains garbled characters\u003C\u002Fp>\u003Cp>Here you can call Veeam's built-in DLL to deserialize data and obtain the correct format.\u003C\u002Fp>\u003Cp>Code example for formatting output strings:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>            int pos1 = v.IndexOf(\"ParamValue=\\\"\");\u003Cbr>            int pos2 = v.IndexOf(\"\u002F&gt;\");\u003Cbr>            String base64en = v.Substring(pos1 + 12, pos2 - pos1 - 14);\u003Cbr>            byte[] data = Convert.FromBase64String(base64en);\u003Cbr>            IList\u003Cveeam.backup.model.cdbcredentialsinfo> result = Veeam.Backup.Core.CProxyBinaryFormatter.Deserialize\u003Cilist\u003Cveeam.backup.model.cdbcredentialsinfo>&gt;(base64en);\u003Cbr>            foreach (var item in result)\u003Cbr>            {\u003Cbr>                Console.WriteLine(\"[+]\");\u003Cbr>                Console.WriteLine(\"DomainName: \" + item.Credentials.DomainName);\u003Cbr>                Console.WriteLine(\"Username: \" + item.Credentials.UserName);\u003Cbr>                Console.WriteLine(\"Password: \" + item.Credentials.GetPassword());\u003Cbr>                Console.WriteLine(\"IsLocalProtect: \" + item.Credentials.IsLocalProtect);\u003Cbr>                Console.WriteLine(\"CurrentUser: \" + item.Credentials.CurrentUser);\u003Cbr>                Console.WriteLine(\"Description: \" + item.Credentials.Description);\u003Cbr>                Console.WriteLine(\"ChangeTimeUtc: \" + item.Credentials.ChangeTimeUtc);\u003Cbr>            }\u003C\u002Filist\u003Cveeam.backup.model.cdbcredentialsinfo>\u003C\u002Fveeam.backup.model.cdbcredentialsinfo>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Need to reference DLL files:\u003C\u002Fp>\u003Cul>\u003Cli>Veeam.Backup.Common.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Configuration.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Interaction.MountService.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Logging.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Model.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Serialization.dll\u003C\u002Fli>\u003Cli>Veeam.TimeMachine.Tool.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The compiled executable must be run on a local system with Veeam installed, otherwise it will error with:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Unhandled Exception: System.ArgumentNullException: Value cannot be null.\u003Cbr>Parameter name: clonableKey\u003Cbr>   at Veeam.Backup.Common.RegistryOptionsWatcher.Create(RegistryKey clonableKey)\u003Cbr>   at Veeam.Backup.Common.CServerOptionsReadStrategy..ctor(Boolean enableFailover)\u003Cbr>   at Veeam.Backup.Common.SOptionsReadStrategy.get_Instance()\u003Cbr>   at Veeam.Backup.Common.SOptions.CreateInstance()\u003Cbr>   at System.Lazy`1.CreateValue()\u003Cbr>   at System.Lazy`1.LazyInitValue()\u003Cbr>   at Veeam.Backup.Common.SOptions.get_Instance()\u003Cbr>   at Veeam.Backup.Common.RestrictedSerializationBinder.EnsureTypeIsAllowed(ValueTuple`2 key)\u003Cbr>   at Veeam.Backup.Common.RestrictedSerializationBinder.ResolveType(ValueTuple`2 key)\u003Cbr>   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)\u003Cbr>   at Veeam.Backup.Common.CustomSerializationBinder.BindToType(String assemblyName, String typeName)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.ObjectReader.Bind(String assemblyString, String typeString)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.ObjectReader.GetType(BinaryAssemblyInfo assemblyInfo, String name)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.ObjectMap..ctor(String objectName, String[] memberNames, BinaryTypeEnum[] binaryTypeEnumA, Object[] typeInformationA, Int32[] memberAssemIds, ObjectReader objectReader, Int32 objectId, BinaryAssemblyInfo assemblyInfo, SizedArray assemIdToAssemblyTable)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.__BinaryParser.ReadObjectWithMapTyped(BinaryObjectWithMapTyped record)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.__BinaryParser.Run()\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.ObjectReader.Deserialize(HeaderHandler handler, __BinaryParser serParser, Boolean fCheck, Boolean isCrossAppDomain, IMethodCallMessage methodCallMessage)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.BinaryFormatter.Deserialize(Stream serializationStream, HeaderHandler handler, Boolean fCheck, Boolean isCrossAppDomain, IMethodCallMessage methodCallMessage)\u003Cbr>   at Veeam.Backup.Core.CProxyBinaryFormatter.BinaryDeserializeObject[T](Byte[] serializedType, BinaryFormatter deserializer)\u003Cbr>   at Veeam.Backup.Core.CProxyBinaryFormatter.Deserialize[T](String input)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result of successful program execution is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019881528_8_3d010f9771.png\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses CVE-2023-27532 as an example to introduce the related issues and solutions for setting up a Veeam Backup &amp; Replication vulnerability debugging environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses CVE-2023-27532 as an example to introduce the method for setting up a Veeam Backup &amp; Replication vulnerability debugging environment.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Debugging Environment Setup\u003C\u002Fli>\u003Cli>Database Credential Extraction\u003C\u002Fli>\u003Cli>Brief Analysis of CVE-2023-27532\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Software Installation\u003C\u002Fh3>\u003Cp>Installation Documentation: https:\u002F\u002Fhelpcenter.veeam.com\u002Farchive\u002Fbackup\u002F110\u002Fvsphere\u002Finstall_vbr.html\u003C\u002Fp>\u003Cp>Software download address: https:\u002F\u002Fwww.veeam.com\u002Fdownload-version.html\u003C\u002Fp>\u003Cp>License application address: https:\u002F\u002Fwww.veeam.com\u002Fsmb-vmware-hyper-v-essentials-download.html\u003C\u002Fp>\u003Cp>Download the ISO file; the license file obtained via email is required during installation.\u003C\u002Fp>\u003Ch3>2. Default directories\u003C\u002Fh3>\u003Cp>Installation directory: C:\\Program Files\\Veeam\\\u003C\u002Fp>\u003Cp>Log path: C:\\ProgramData\\Veeam\\Backup\u003C\u002Fp>\u003Ch3>3. Default ports\u003C\u002Fh3>\u003Cul>\u003Cli>Veeam.Backup.Service ports: 9392, 9401 (SSL)\u003C\u002Fli>\u003Cli>Veeam.Backup.ConfigurationService port: 9380\u003C\u002Fli>\u003Cli>Veeam.Backup.CatalogDataService port: 9393\u003C\u002Fli>\u003Cli>Veeam.Backup.EnterpriseService port: 9394\u003C\u002Fli>\u003Cli>Web UI ports: 9080, 9443 (SSL)\u003C\u002Fli>\u003Cli>RESTful API ports: 9399, 9398 (SSL)\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Debug environment setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Locate Process\u003C\u002Fh3>\u003Cp>Execute command: netstat -ano | findstr 9401\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>TCP    0.0.0.0:9401           0.0.0.0:0              LISTENING       7132\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Located process PID is 7132, process name is Veeam.Backup.Service.exe\u003C\u002Fp>\u003Cp>Use dnSpy to attach to process Veeam.Backup.Service.exe\u003C\u002Fp>\u003Ch3>2. Debug Settings\u003C\u002Fh3>\u003Cp>To view variable contents during debugging, create the following files:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.Service.ini\u003C\u002Fli>\u003Cli>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.DBManager.ini\u003C\u002Fli>\u003Cli>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.ServiceLib.ini\u003C\u002Fli>\u003Cli>C:\\Program Files\\Veeam\\Backup and Replication\\Backup\\Veeam.Backup.Interaction.MountService.ini\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Content is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[.NET Framework Debugging Control]\u003Cbr>Generate TrackingInfo=1\u003Cbr>AllowOptimize=0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart Service\u003C\u002Fp>\u003Ch2>0x04 Database Credential Extraction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain Database Connection Configuration\u003C\u002Fh3>\u003Ch4>(1) Obtain Database Connection Port\u003C\u002Fh4>\u003Cp>Open SQL Server 2016 Configuration Manager, select SQL Server Services, you can see that the Process ID corresponding to SQL Server (VEEAMSQL2016) is 1756, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019800797_0_78672cdc73-1.png\">\u003C\u002Fp>\u003Cp>Check the port corresponding to the process: netstat -ano|findstr 1756\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>  TCP    0.0.0.0:49720          0.0.0.0:0              LISTENING       1756\u003Cbr>  TCP    [::]:49720             [::]:0                 LISTENING       1756\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain connection port 49720\u003C\u002Fp>\u003Ch4>(2) Obtain Database Name\u003C\u002Fh4>\u003Cp>Method 1:\u003C\u002Fp>\u003Cp>Enter the Configuration Database Connection Settings page, where you can see the Database name as VeeamBackup and the authentication method as Windows Authentication, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019815475_1_d54e265606-1.png\">\u003C\u002Fp>\u003Cp>Method 2:\u003C\u002Fp>\u003Cp>Read the registry key value: REG QUERY \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Veeam\\Veeam Backup and Replication\" \u002Fv SqlDatabaseName\u003C\u002Fp>\u003Ch3>2. Database Connection\u003C\u002Fh3>\u003Ch4>(1) Using the Interface Program\u003C\u002Fh4>\u003Cp>Here, DbSchema is used.\u003C\u002Fp>\u003Cp>Select SqlServer and configure as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019826343_2_5d2d1e3429-1.png\">\u003C\u002Fp>\u003Cp>Successfully connected as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019839167_3_24d4e9583b-1.png\">\u003C\u002Fp>\u003Cp>Select the database VeeamBackup.dbo, enter the database page, and globally search for the keyword 'password' to obtain the relevant query statement:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT\u003Cbr>\tid, user_name, password, usn, description, visible, change_time_utc\u003Cbr>FROM\u003Cbr>\tVeeamBackup.dbo.Credentials s;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, obtain the credential information stored in the database, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019860608_4_9ab8c7a766-1.png\">\u003C\u002Fp>\u003Ch4>(2) Using Powershell\u003C\u002Fh4>\u003Cp>Reference: https:\u002F\u002Fgithub.com\u002Fsadshade\u002Fveeam-creds\u003C\u002Fp>\u003Cp>veeam-creds will report an error when tested on Veeam Backup and Replication 11 and later versions, with the prompt:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Exception calling \"Fill\" with \"1\" argument(s): \"[DBNETLIB][ConnectionOpen (SECDoClientHandshake()).]SSL Security error.\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This is because https:\u002F\u002Fgithub.com\u002Fsadshade\u002Fveeam-creds\u002Fblob\u002Fmain\u002FVeeam-Get-Creds.ps1#L32 uses sqloledb, and the sqloledb on the current system has expired\u003C\u002Fp>\u003Cp>Here you can choose to use MSOLEDBSQL or MSOLEDBSQL19 to resolve the issue\u003C\u002Fp>\u003Cp>PowerShell command to check if MSOLEDBSQL or MSOLEDBSQL19 is installed on the current system: (New-Object System.Data.OleDb.OleDbEnumerator).GetElements() | select SOURCES_NAME, SOURCES_DESCRIPTION\u003C\u002Fp>\u003Cp>Example of returned results:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SOURCES_NAME               SOURCES_DESCRIPTION\u003Cbr>------------               -------------------\u003Cbr>SQLOLEDB                   Microsoft OLE DB Provider for SQL Server\u003Cbr>MSOLEDBSQL19 Enumerator    Microsoft OLE DB Driver 19 for SQL Server Enumerator\u003Cbr>MSDataShape                MSDataShape\u003Cbr>SQLNCLI11                  SQL Server Native Client 11.0\u003Cbr>ADsDSOObject               OLE DB Provider for Microsoft Directory Services\u003Cbr>SQLNCLIRDA11               SQL Server Native Client RDA 11.0\u003Cbr>SQLNCLI11 Enumerator       SQL Server Native Client 11.0 Enumerator\u003Cbr>Windows Search Data Source Microsoft OLE DB Provider for Search\u003Cbr>SQLNCLIRDA11 Enumerator    SQL Server Native Client RDA 11.0 Enumerator\u003Cbr>SSISOLEDB                  OLE DB Provider for SQL Server Integration Services\u003Cbr>MSDASQL                    Microsoft OLE DB Provider for ODBC Drivers\u003Cbr>MSDASQL Enumerator         Microsoft OLE DB Enumerator for ODBC Drivers\u003Cbr>SQLOLEDB Enumerator        Microsoft OLE DB Enumerator for SQL Server\u003Cbr>MSDAOSP                    Microsoft OLE DB Simple Provider\u003Cbr>MSOLEDBSQL19               Microsoft OLE DB Driver 19 for SQL Server\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The above results show that MSOLEDBSQL19 is installed on the current system, so simply replace sqloledb with MSOLEDBSQL19.\u003C\u002Fp>\u003Ch4>Note: Method for installing MSOLEDBSQL or MSOLEDBSQL19.\u003C\u002Fh4>\u003Cp>Download address: https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fsql\u002Fconnect\u002Foledb\u002Fdownload-oledb-driver-for-sql-server?source=recommendations&amp;view=sql-server-ver16\u003C\u002Fp>\u003Cp>Command line installation method: msiexec \u002Fi msoledbsql.msi \u002Fqn IACCEPTMSOLEDBSQLLICENSETERMS=YES\u003C\u002Fp>\u003Cp>Microsoft Visual C++ Redistributable version must be at least 14.34 before installation\u003C\u002Fp>\u003Cp>Simple method to check Microsoft Visual C++ Redistributable version:\u003C\u002Fp>\u003Cp>Obtain via folder name: dir \u002Fo:-d \"C:\\ProgramData\\Package Cache\"\u003C\u002Fp>\u003Cp>Example return results:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{88a5e14d-0f76-42fd-a259-a53b8fde6c73}\u003Cbr>{7F2142C4-0C90-4792-89BF-5DF5E2306E59}v24.64.30112\u003Cbr>{FE134959-3504-4B60-9642-0FBBAF76B779}v24.64.30112\u003Cbr>{DF700CFE-0603-47E1-A45D-3369AD751E7E}v24.64.30112\u003Cbr>{4b6a8b46-ac89-45e8-8871-0be420bf9fa0}\u003Cbr>{529D20E8-132A-4F1A-A25F-9211B8C943AC}v14.29.30037\u003Cbr>{C874FB5A-1C85-460A-A4A9-CBCC3FAE7880}v14.29.30037\u003Cbr>{4b2f3795-f407-415e-88d5-8c8ab322909d}\u003Cbr>{C9DE51F8-7846-4621-815D-E8AFD3E3C0FF}v14.20.27508\u003Cbr>{B96F6FA1-530F-42F1-9F71-33C583716340}v14.20.27508\u003Cbr>{8c3f057e-d6a6-4338-ac6a-f1c795a6577b}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>From this, it can be concluded that the Microsoft Visual C++ Redistributable version is 14.29.30037. A higher version of Microsoft Visual C++ Redistributable needs to be installed. Download link: https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fcpp\u002Fwindows\u002Flatest-supported-vc-redist?view=msvc-170\u003C\u002Fp>\u003Cp>Both x86 and x64 need to be installed. veeam-creds runs successfully as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019866476_5_60307851d1-1.png\">\u003C\u002Fp>\u003Ch2>0x05 Brief Analysis of CVE-2023-27532\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Y4er published a POC that calls CredentialsDbScopeGetAllCreds to obtain plaintext credentials: https:\u002F\u002Fy4er.com\u002Fposts\u002Fcve-2023-27532-veeam-backup-replication-leaked-credentials\u002F\u003C\u002Fp>\u003Ch3>1. Credential Location\u003C\u002Fh3>\u003Cp>The plaintext credentials here correspond to the location: Veeam Backup &amp; Replication Console -&gt; Manage Credentials. The default plaintext password is empty, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870169_6_2e29fd8646-1.png\">\u003C\u002Fp>\u003Cp>The debugging breakpoint location is Veeam.Backup.DBManager.dll -&gt; CCredentialsDbScope, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019875098_7_5cb236a3d9-1.png\">\u003C\u002Fp>\u003Ch3>2. Data Parsing\u003C\u002Fh3>\u003Cp>The final return result of the POC is serialized XML. After Base64 decoding ParamValue, plaintext data can be seen, but the format is incorrect and contains garbled characters\u003C\u002Fp>\u003Cp>Here you can call Veeam's built-in DLL to deserialize data and obtain the correct format.\u003C\u002Fp>\u003Cp>Code example for formatting output strings:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>            int pos1 = v.IndexOf(\"ParamValue=\\\"\");\u003Cbr>            int pos2 = v.IndexOf(\"\u002F&gt;\");\u003Cbr>            String base64en = v.Substring(pos1 + 12, pos2 - pos1 - 14);\u003Cbr>            byte[] data = Convert.FromBase64String(base64en);\u003Cbr>            IList\u003Cveeam.backup.model.cdbcredentialsinfo> result = Veeam.Backup.Core.CProxyBinaryFormatter.Deserialize\u003Cilist\u003Cveeam.backup.model.cdbcredentialsinfo>&gt;(base64en);\u003Cbr>            foreach (var item in result)\u003Cbr>            {\u003Cbr>                Console.WriteLine(\"[+]\");\u003Cbr>                Console.WriteLine(\"DomainName: \" + item.Credentials.DomainName);\u003Cbr>                Console.WriteLine(\"Username: \" + item.Credentials.UserName);\u003Cbr>                Console.WriteLine(\"Password: \" + item.Credentials.GetPassword());\u003Cbr>                Console.WriteLine(\"IsLocalProtect: \" + item.Credentials.IsLocalProtect);\u003Cbr>                Console.WriteLine(\"CurrentUser: \" + item.Credentials.CurrentUser);\u003Cbr>                Console.WriteLine(\"Description: \" + item.Credentials.Description);\u003Cbr>                Console.WriteLine(\"ChangeTimeUtc: \" + item.Credentials.ChangeTimeUtc);\u003Cbr>            }\u003C\u002Filist\u003Cveeam.backup.model.cdbcredentialsinfo>\u003C\u002Fveeam.backup.model.cdbcredentialsinfo>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Need to reference DLL files:\u003C\u002Fp>\u003Cul>\u003Cli>Veeam.Backup.Common.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Configuration.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Interaction.MountService.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Logging.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Model.dll\u003C\u002Fli>\u003Cli>Veeam.Backup.Serialization.dll\u003C\u002Fli>\u003Cli>Veeam.TimeMachine.Tool.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The compiled executable must be run on a local system with Veeam installed, otherwise it will error with:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Unhandled Exception: System.ArgumentNullException: Value cannot be null.\u003Cbr>Parameter name: clonableKey\u003Cbr>   at Veeam.Backup.Common.RegistryOptionsWatcher.Create(RegistryKey clonableKey)\u003Cbr>   at Veeam.Backup.Common.CServerOptionsReadStrategy..ctor(Boolean enableFailover)\u003Cbr>   at Veeam.Backup.Common.SOptionsReadStrategy.get_Instance()\u003Cbr>   at Veeam.Backup.Common.SOptions.CreateInstance()\u003Cbr>   at System.Lazy`1.CreateValue()\u003Cbr>   at System.Lazy`1.LazyInitValue()\u003Cbr>   at Veeam.Backup.Common.SOptions.get_Instance()\u003Cbr>   at Veeam.Backup.Common.RestrictedSerializationBinder.EnsureTypeIsAllowed(ValueTuple`2 key)\u003Cbr>   at Veeam.Backup.Common.RestrictedSerializationBinder.ResolveType(ValueTuple`2 key)\u003Cbr>   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)\u003Cbr>   at Veeam.Backup.Common.CustomSerializationBinder.BindToType(String assemblyName, String typeName)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.ObjectReader.Bind(String assemblyString, String typeString)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.ObjectReader.GetType(BinaryAssemblyInfo assemblyInfo, String name)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.ObjectMap..ctor(String objectName, String[] memberNames, BinaryTypeEnum[] binaryTypeEnumA, Object[] typeInformationA, Int32[] memberAssemIds, ObjectReader objectReader, Int32 objectId, BinaryAssemblyInfo assemblyInfo, SizedArray assemIdToAssemblyTable)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.__BinaryParser.ReadObjectWithMapTyped(BinaryObjectWithMapTyped record)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.__BinaryParser.Run()\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.ObjectReader.Deserialize(HeaderHandler handler, __BinaryParser serParser, Boolean fCheck, Boolean isCrossAppDomain, IMethodCallMessage methodCallMessage)\u003Cbr>   at System.Runtime.Serialization.Formatters.Binary.BinaryFormatter.Deserialize(Stream serializationStream, HeaderHandler handler, Boolean fCheck, Boolean isCrossAppDomain, IMethodCallMessage methodCallMessage)\u003Cbr>   at Veeam.Backup.Core.CProxyBinaryFormatter.BinaryDeserializeObject[T](Byte[] serializedType, BinaryFormatter deserializer)\u003Cbr>   at Veeam.Backup.Core.CProxyBinaryFormatter.Deserialize[T](String input)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result of successful program execution is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019881528_8_3d010f9771-1.png\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses CVE-2023-27532 as an example to introduce the related issues and solutions for setting up a Veeam Backup &amp; Replication vulnerability debugging environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1526,"Onedaysec",5,"published","2026-02-02T08:19:47.662Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Veeam Backup & Replication Debug Setup & CVE-2023-27532 Analysis","Veeam Backup, vulnerability debugging, CVE-2023-27532, database credential extraction, environment setup",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],193,192,190,189,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.774Z","2026-07-23T16:01:09.919Z","draft","2026-07-23T16:04:25.024Z"]