[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRO5E9i0zWqa9sp6UTEANwB90Ho0SbOHKDodklE7IzGA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},75,"What SQL queries can I run to export virtual machine and ESXi host configuration from vCenter's database?","After connecting to the VCDB database, run `SELECT * FROM vc.vpx_vm;` to retrieve VM configuration (e.g., file_name, guest_os, ip_address) and `SELECT * FROM vc.vpx_host;` for ESXi host info. For ESXi passwords, use `SELECT name,username,password FROM vc.vpxv_hosts;` to get the encrypted vpxuser password. These commands are essential for penetration testing as explained in [vSphere Development Guide 4 - PostgreSQL](\u002Fnews\u002Fvsphere-development-guide-4-postgresql).","\u003Cp>After connecting to the VCDB database, run `SELECT * FROM vc.vpx_vm;` to retrieve VM configuration (e.g., file_name, guest_os, ip_address) and `SELECT * FROM vc.vpx_host;` for ESXi host info. For ESXi passwords, use `SELECT name,username,password FROM vc.vpxv_hosts;` to get the encrypted vpxuser password. These commands are essential for penetration testing as explained in [vSphere Development Guide 4 - PostgreSQL](\u002Fnews\u002Fvsphere-development-guide-4-postgresql).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvsphere-development-guide-4-postgresql\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-sql-queries-can-i-run-to-export-virtual-machine-and-esxi-host-configuration-1777485231740","SQL query, vpx_vm, vpx_host, vpxv_hosts, virtual machine configuration, ESXi configuration",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},20,"vSphere Development Guide 4 - PostgreSQL","vsphere-development-guide-4-postgresql","Learn to export virtual machine configuration from vCenter's PostgreSQL database using psql commands and Go programming for automation.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous three articles \"vSphere Development Guide 1 - vSphere Automation API\", \"vSphere Development Guide 2 - vSphere Web Services API\", and \"vSphere Development Guide 3 - VMware PowerCLI\" introduced methods for interacting with virtual machines and remotely exporting their configuration information. This article will introduce the method of exporting virtual machine configuration information through the PostgreSQL database on vCenter.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Export Method\u003C\u002Fli>\u003Cli>Program Implementation\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Export Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>vCenter comes with a PostgreSQL database installed by default, used to store VM and ESXi information.\u003C\u002Fp>\u003Cp>As mentioned in the previous article \"Confluence Exploitation Guide\":\u003C\u002Fp>\u003Cp>After PostgreSQL installation, a user named 'postgres' is created on the local operating system, with no default password.\u003C\u002Fp>\u003Cp>If the password for the user 'postgres' is not set, you can connect to the PostgreSQL database using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -h localhost -U postgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019786823_0_f809450ef4.jpeg\">\u003C\u002Fp>\u003Cp>The default user list is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019797700_1_b4056301b0.jpeg\">\u003C\u002Fp>\u003Cp>If the password for user postgres is set and cannot be obtained, you can choose to operate with user vc. The command to connect to the PostgreSQL database is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -h localhost -d VCDB -U vc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019809703_2_6ea7db7863.jpeg\">\u003C\u002Fp>\u003Cp>The plaintext password for user vc is stored in the fixed file \u002Fetc\u002Fvmware-vpx\u002Fvcdb.properties\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>psql does not support directly passing the password as a parameter; an interactive environment is required for operation\u003C\u002Fp>\u003Cp>After connecting to the PostgreSQL database, the command to query virtual machine configuration information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT * FROM vc.vpx_vm;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After connecting to the PostgreSQL database, the command to query ESXi configuration information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT * FROM vc.vpx_host;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For ease of use, connecting to the PostgreSQL database and query commands can be combined. Here are two example commands:\u003C\u002Fp>\u003Ch4>(1) Using the postgres user to query virtual machine configuration information\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -h localhost -U postgres -c \"SELECT file_name,guest_os,ip_address FROM vc.vpx_vm;\" -d VCDB\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using the vc user to query ESXI configuration information\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -h localhost -U vc -c \"SELECT name,username,password,password_last_upd_dt FROM vc.vpxv_hosts;\" -d VCDB -W\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>psql does not support directly passing a password as a parameter. If the user has set a password, it needs to be entered again in an interactive environment.\u003C\u002Fp>\u003Ch2>0x03 Program Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since psql does not support directly passing a password as a parameter, writing a program to implement database connection and query configuration can be considered.\u003C\u002Fp>\u003Cp>Considering both applicability and convenience, the Go language is chosen as the development language.\u003C\u002Fp>\u003Cp>The third-party package for PostgreSQL support is selected from https:\u002F\u002Fgithub.com\u002Fbmizerany\u002Fpq\u003C\u002Fp>\u003Ch3>1. Install the third-party package\u003C\u002Fh3>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>go get github.com\u002Flib\u002Fpq\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Writing code\u003C\u002Fh3>\u003Cp>Third-party packages installed via go get github.com\u002Flib\u002Fpq will have bugs when used under vCenter, displaying an error 'setting PGSERVICEFILE not supported' when connecting to the database.\u003C\u002Fp>\u003Cp>This is because the vCenter environment sets the environment variable $PGSERVICEFILE by default, and the third-party package installed via go get github.com\u002Flib\u002Fpq references this variable by default, leading to the error.\u003C\u002Fp>\u003Cp>Location of the error code: %GOPATH%\\src\\github.com\\lib\\pq\\conn.go, Line 1988-1989, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019822148_3_61a4a35f8c.jpeg\">\u003C\u002Fp>\u003Cp>The code on GitHub has already fixed this bug, code address: https:\u002F\u002Fgithub.com\u002Fbmizerany\u002Fpq\u002Fblob\u002Fmaster\u002Fconn.go#L644\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019832405_4_44d26ca973.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, we only need to comment out lines 1988 and 1989 in %GOPATH%\\src\\github.com\\lib\\pq\\conn.go, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019850297_5_dfcd885595.jpeg\">\u003C\u002Fp>\u003Cp>In terms of code implementation, first read the file \u002Fetc\u002Fvmware-vpx\u002Fvcdb.properties to obtain the plaintext password of user vc, then use user vc to connect to the PostgreSQL database, and finally export the virtual machine configuration information.\u003C\u002Fp>\u003Cp>The complete implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>package main\u003Cbr>\u003Cbr>import (\u003Cbr>\t\"database\u002Fsql\"\u003Cbr>\t\"fmt\"\u003Cbr>\t\"strings\"\u003Cbr>\t\"io\u002Fioutil\"\u003Cbr>\t_ \"github.com\u002Flib\u002Fpq\"\u003Cbr>)\u003Cbr>\u003Cbr>\u003Cbr>func connectDB() *sql.DB{\u003Cbr>\tfmt.Println(\"[+] Get the config\")\u003Cbr>\tb, err := ioutil.ReadFile(\"\u002Fetc\u002Fvmware-vpx\u002Fvcdb.properties\")\u003Cbr>    if err != nil {\u003Cbr>        fmt.Print(err)\u003Cbr>    }\u003Cbr>\u003Cbr>\tstr := string(b)\u003Cbr>\tfmt.Println(str)\u003Cbr>\tindex1 := strings.Index(str,\"password\")\u003Cbr>\tindex2 := strings.Index(str,\"password.encrypted\")\u003Cbr>\tpassword := b[index1+11:index2]\u003Cbr>\u003Cbr>\tvar host     = \"localhost\"\u003Cbr>\tvar port int = 5432\u003Cbr>\tvar user     = \"vc\"\u003Cbr>\tvar dbname   = \"VCDB\"\u003Cbr>\u003Cbr>\tpsqlInfo := fmt.Sprintf(\"host=%s port=%d user=%s \"+\u003Cbr>\t\t\"password=%s dbname=%s sslmode=disable\",\u003Cbr>\t\thost, port, user, password, dbname)\u003Cbr>\u003Cbr>\tfmt.Println(\"[*] psqlInfo:\" + psqlInfo)\u003Cbr>\tdb, err := sql.Open(\"postgres\", psqlInfo)\u003Cbr>\tif err != nil {\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>\u003Cbr>\terr = db.Ping()\u003Cbr>\tif err != nil {\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>\tfmt.Println(\"[+] Successfully connected!\")\u003Cbr>\treturn db\u003Cbr>}\u003Cbr>\u003Cbr>\u003Cbr>func queryVM(db *sql.DB){\u003Cbr>\tvar file_name,guest_os,ip_address,power_state string\u003Cbr>\u003Cbr>\tfmt.Println(\"[*] Querying VM\")\u003Cbr>\trows,err:=db.Query(\"SELECT file_name,guest_os,ip_address,power_state FROM vc.vpx_vm\")\u003Cbr>\u003Cbr>\tif err!= nil{\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>\tdefer rows.Close()\u003Cbr>\tfor rows.Next(){\u003Cbr>\terr:= rows.Scan(&amp;file_name,&amp;guest_os,&amp;ip_address,&amp;power_state)\u003Cbr>\tif err!= nil{\u003Cbr>\t\t\u002F\u002Ffmt.Println(err)\u003Cbr>\t}\u003Cbr>\tfmt.Println(\" - file_name   : \" + file_name)\u003Cbr>\tfmt.Println(\"   guest_os    : \" + guest_os)\u003Cbr>\tfmt.Println(\"   ip_address  : \" + ip_address)\u003Cbr>\tfmt.Println(\"   power_state : \" + power_state)\u003Cbr>}\u003Cbr>err = rows.Err()\u003Cbr>if err!= nil{\u003Cbr>\tpanic(err)\u003Cbr>}\u003Cbr>}\u003Cbr>\u003Cbr>\u003Cbr>func queryESXI(db *sql.DB){\u003Cbr>\tvar name,username,password,password_last_upd_dt string\u003Cbr>\u003Cbr>\tfmt.Println(\"[*] Querying ESXI\")\u003Cbr>\trows,err:=db.Query(\"SELECT name,username,password,password_last_upd_dt FROM vc.vpxv_hosts\")\u003Cbr>\u003Cbr>\tif err!= nil{\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>\tdefer rows.Close()\u003Cbr>\tfor rows.Next(){\u003Cbr>\t\terr:= rows.Scan(&amp;name,&amp;username,&amp;password,&amp;password_last_upd_dt)\u003Cbr>\t\tif err!= nil{\u003Cbr>\t\t\t\u002F\u002Ffmt.Println(err)\u003Cbr>\t\t}\u003Cbr>\t\tfmt.Println(\" - name         : \" + name)\u003Cbr>\t\tfmt.Println(\"   username     : \" + username)\u003Cbr>\t\tfmt.Println(\"   password     : \" + password)\u003Cbr>\t\tfmt.Println(\"   password_last: \" + password_last_upd_dt)\u003Cbr>\u003Cbr>\t}\u003Cbr>\terr = rows.Err()\u003Cbr>\tif err != nil {\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>}\u003Cbr>\u003Cbr>\u003Cbr>func main() {\u003Cbr>\tdb := connectDB()\u003Cbr>\tqueryVM(db)\u003Cbr>\tqueryESXI(db)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Cross-platform compilation\u003C\u002Fh3>\u003Cp>Save the above code as main.go\u003C\u002Fp>\u003Cp>The command to compile into a Linux version is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET CGO_ENABLED=0\u003Cbr>SET GOOS=linux\u003Cbr>SET GOARCH=amd64\u003Cbr>go build -o vCenter_Query_PostgreSQL\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Testing\u003C\u002Fh3>\u003Cp>Execute vCenter_Query_PostgreSQL on vCenter to automatically export configuration information of virtual machines and ESXi hosts\u003C\u002Fp>\u003Ch3>Supplement:\u003C\u002Fh3>\u003Cp>Execute the command SELECT name,username,password,password_last_upd_dt FROM vc.vpxv_hosts; to export the encrypted password of the vpxuser account\u003C\u002Fp>\u003Cp>When an ESXi host connects to vCenter, the ESXi host creates a root-privileged user named vpxuser\u003C\u002Fp>\u003Cp>By default, vCenter Server uses the OpenSSL cryptographic library as a random source to generate a new vpxuser password every 30 days, with a password length of 32 characters\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article describes the method of exporting virtual machine configuration information through the PostgreSQL database on vCenter, which is an extremely important step in penetration testing.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous three articles \"vSphere Development Guide 1 - vSphere Automation API\", \"vSphere Development Guide 2 - vSphere Web Services API\", and \"vSphere Development Guide 3 - VMware PowerCLI\" introduced methods for interacting with virtual machines and remotely exporting their configuration information. This article will introduce the method of exporting virtual machine configuration information through the PostgreSQL database on vCenter.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Export Method\u003C\u002Fli>\u003Cli>Program Implementation\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Export Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>vCenter comes with a PostgreSQL database installed by default, used to store VM and ESXi information.\u003C\u002Fp>\u003Cp>As mentioned in the previous article \"Confluence Exploitation Guide\":\u003C\u002Fp>\u003Cp>After PostgreSQL installation, a user named 'postgres' is created on the local operating system, with no default password.\u003C\u002Fp>\u003Cp>If the password for the user 'postgres' is not set, you can connect to the PostgreSQL database using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -h localhost -U postgres\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019786823_0_f809450ef4-1.jpeg\">\u003C\u002Fp>\u003Cp>The default user list is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019797700_1_b4056301b0-1.jpeg\">\u003C\u002Fp>\u003Cp>If the password for user postgres is set and cannot be obtained, you can choose to operate with user vc. The command to connect to the PostgreSQL database is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -h localhost -d VCDB -U vc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019809703_2_6ea7db7863-1.jpeg\">\u003C\u002Fp>\u003Cp>The plaintext password for user vc is stored in the fixed file \u002Fetc\u002Fvmware-vpx\u002Fvcdb.properties\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>psql does not support directly passing the password as a parameter; an interactive environment is required for operation\u003C\u002Fp>\u003Cp>After connecting to the PostgreSQL database, the command to query virtual machine configuration information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT * FROM vc.vpx_vm;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After connecting to the PostgreSQL database, the command to query ESXi configuration information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT * FROM vc.vpx_host;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For ease of use, connecting to the PostgreSQL database and query commands can be combined. Here are two example commands:\u003C\u002Fp>\u003Ch4>(1) Using the postgres user to query virtual machine configuration information\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -h localhost -U postgres -c \"SELECT file_name,guest_os,ip_address FROM vc.vpx_vm;\" -d VCDB\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using the vc user to query ESXI configuration information\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>psql -h localhost -U vc -c \"SELECT name,username,password,password_last_upd_dt FROM vc.vpxv_hosts;\" -d VCDB -W\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>psql does not support directly passing a password as a parameter. If the user has set a password, it needs to be entered again in an interactive environment.\u003C\u002Fp>\u003Ch2>0x03 Program Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since psql does not support directly passing a password as a parameter, writing a program to implement database connection and query configuration can be considered.\u003C\u002Fp>\u003Cp>Considering both applicability and convenience, the Go language is chosen as the development language.\u003C\u002Fp>\u003Cp>The third-party package for PostgreSQL support is selected from https:\u002F\u002Fgithub.com\u002Fbmizerany\u002Fpq\u003C\u002Fp>\u003Ch3>1. Install the third-party package\u003C\u002Fh3>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>go get github.com\u002Flib\u002Fpq\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Writing code\u003C\u002Fh3>\u003Cp>Third-party packages installed via go get github.com\u002Flib\u002Fpq will have bugs when used under vCenter, displaying an error 'setting PGSERVICEFILE not supported' when connecting to the database.\u003C\u002Fp>\u003Cp>This is because the vCenter environment sets the environment variable $PGSERVICEFILE by default, and the third-party package installed via go get github.com\u002Flib\u002Fpq references this variable by default, leading to the error.\u003C\u002Fp>\u003Cp>Location of the error code: %GOPATH%\\src\\github.com\\lib\\pq\\conn.go, Line 1988-1989, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019822148_3_61a4a35f8c-1.jpeg\">\u003C\u002Fp>\u003Cp>The code on GitHub has already fixed this bug, code address: https:\u002F\u002Fgithub.com\u002Fbmizerany\u002Fpq\u002Fblob\u002Fmaster\u002Fconn.go#L644\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019832405_4_44d26ca973-1.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, we only need to comment out lines 1988 and 1989 in %GOPATH%\\src\\github.com\\lib\\pq\\conn.go, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019850297_5_dfcd885595-1.jpeg\">\u003C\u002Fp>\u003Cp>In terms of code implementation, first read the file \u002Fetc\u002Fvmware-vpx\u002Fvcdb.properties to obtain the plaintext password of user vc, then use user vc to connect to the PostgreSQL database, and finally export the virtual machine configuration information.\u003C\u002Fp>\u003Cp>The complete implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>package main\u003Cbr>\u003Cbr>import (\u003Cbr>\t\"database\u002Fsql\"\u003Cbr>\t\"fmt\"\u003Cbr>\t\"strings\"\u003Cbr>\t\"io\u002Fioutil\"\u003Cbr>\t_ \"github.com\u002Flib\u002Fpq\"\u003Cbr>)\u003Cbr>\u003Cbr>\u003Cbr>func connectDB() *sql.DB{\u003Cbr>\tfmt.Println(\"[+] Get the config\")\u003Cbr>\tb, err := ioutil.ReadFile(\"\u002Fetc\u002Fvmware-vpx\u002Fvcdb.properties\")\u003Cbr>    if err != nil {\u003Cbr>        fmt.Print(err)\u003Cbr>    }\u003Cbr>\u003Cbr>\tstr := string(b)\u003Cbr>\tfmt.Println(str)\u003Cbr>\tindex1 := strings.Index(str,\"password\")\u003Cbr>\tindex2 := strings.Index(str,\"password.encrypted\")\u003Cbr>\tpassword := b[index1+11:index2]\u003Cbr>\u003Cbr>\tvar host     = \"localhost\"\u003Cbr>\tvar port int = 5432\u003Cbr>\tvar user     = \"vc\"\u003Cbr>\tvar dbname   = \"VCDB\"\u003Cbr>\u003Cbr>\tpsqlInfo := fmt.Sprintf(\"host=%s port=%d user=%s \"+\u003Cbr>\t\t\"password=%s dbname=%s sslmode=disable\",\u003Cbr>\t\thost, port, user, password, dbname)\u003Cbr>\u003Cbr>\tfmt.Println(\"[*] psqlInfo:\" + psqlInfo)\u003Cbr>\tdb, err := sql.Open(\"postgres\", psqlInfo)\u003Cbr>\tif err != nil {\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>\u003Cbr>\terr = db.Ping()\u003Cbr>\tif err != nil {\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>\tfmt.Println(\"[+] Successfully connected!\")\u003Cbr>\treturn db\u003Cbr>}\u003Cbr>\u003Cbr>\u003Cbr>func queryVM(db *sql.DB){\u003Cbr>\tvar file_name,guest_os,ip_address,power_state string\u003Cbr>\u003Cbr>\tfmt.Println(\"[*] Querying VM\")\u003Cbr>\trows,err:=db.Query(\"SELECT file_name,guest_os,ip_address,power_state FROM vc.vpx_vm\")\u003Cbr>\u003Cbr>\tif err!= nil{\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>\tdefer rows.Close()\u003Cbr>\tfor rows.Next(){\u003Cbr>\terr:= rows.Scan(&amp;file_name,&amp;guest_os,&amp;ip_address,&amp;power_state)\u003Cbr>\tif err!= nil{\u003Cbr>\t\t\u002F\u002Ffmt.Println(err)\u003Cbr>\t}\u003Cbr>\tfmt.Println(\" - file_name   : \" + file_name)\u003Cbr>\tfmt.Println(\"   guest_os    : \" + guest_os)\u003Cbr>\tfmt.Println(\"   ip_address  : \" + ip_address)\u003Cbr>\tfmt.Println(\"   power_state : \" + power_state)\u003Cbr>}\u003Cbr>err = rows.Err()\u003Cbr>if err!= nil{\u003Cbr>\tpanic(err)\u003Cbr>}\u003Cbr>}\u003Cbr>\u003Cbr>\u003Cbr>func queryESXI(db *sql.DB){\u003Cbr>\tvar name,username,password,password_last_upd_dt string\u003Cbr>\u003Cbr>\tfmt.Println(\"[*] Querying ESXI\")\u003Cbr>\trows,err:=db.Query(\"SELECT name,username,password,password_last_upd_dt FROM vc.vpxv_hosts\")\u003Cbr>\u003Cbr>\tif err!= nil{\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>\tdefer rows.Close()\u003Cbr>\tfor rows.Next(){\u003Cbr>\t\terr:= rows.Scan(&amp;name,&amp;username,&amp;password,&amp;password_last_upd_dt)\u003Cbr>\t\tif err!= nil{\u003Cbr>\t\t\t\u002F\u002Ffmt.Println(err)\u003Cbr>\t\t}\u003Cbr>\t\tfmt.Println(\" - name         : \" + name)\u003Cbr>\t\tfmt.Println(\"   username     : \" + username)\u003Cbr>\t\tfmt.Println(\"   password     : \" + password)\u003Cbr>\t\tfmt.Println(\"   password_last: \" + password_last_upd_dt)\u003Cbr>\u003Cbr>\t}\u003Cbr>\terr = rows.Err()\u003Cbr>\tif err != nil {\u003Cbr>\t\tpanic(err)\u003Cbr>\t}\u003Cbr>}\u003Cbr>\u003Cbr>\u003Cbr>func main() {\u003Cbr>\tdb := connectDB()\u003Cbr>\tqueryVM(db)\u003Cbr>\tqueryESXI(db)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Cross-platform compilation\u003C\u002Fh3>\u003Cp>Save the above code as main.go\u003C\u002Fp>\u003Cp>The command to compile into a Linux version is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SET CGO_ENABLED=0\u003Cbr>SET GOOS=linux\u003Cbr>SET GOARCH=amd64\u003Cbr>go build -o vCenter_Query_PostgreSQL\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Testing\u003C\u002Fh3>\u003Cp>Execute vCenter_Query_PostgreSQL on vCenter to automatically export configuration information of virtual machines and ESXi hosts\u003C\u002Fp>\u003Ch3>Supplement:\u003C\u002Fh3>\u003Cp>Execute the command SELECT name,username,password,password_last_upd_dt FROM vc.vpxv_hosts; to export the encrypted password of the vpxuser account\u003C\u002Fp>\u003Cp>When an ESXi host connects to vCenter, the ESXi host creates a root-privileged user named vpxuser\u003C\u002Fp>\u003Cp>By default, vCenter Server uses the OpenSSL cryptographic library as a random source to generate a new vpxuser password every 30 days, with a password length of 32 characters\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article describes the method of exporting virtual machine configuration information through the PostgreSQL database on vCenter, which is an extremely important step in penetration testing.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1746,"Onedaysec",5,"published","2026-02-02T08:20:05.024Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"vSphere PostgreSQL Guide: Export VM Config from vCenter DB","vSphere PostgreSQL, vCenter database, VM configuration export, vSphere development, PostgreSQL vCenter",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],77,76,74,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.598Z","2026-07-23T16:00:58.385Z","draft","2026-07-23T16:03:23.448Z"]