Tutorial How to get SQA rights on TeamSpeak Server (not yours :)

Supervisor

Administrator
Apr 27, 2015
1,863
2,546
335
OK, so basically.. this is about getting SQA (Server Query Admin) on a rented server.

Required:
  • YATQA
What to do:
  1. Create your own server, copy all SQA permissions to your client
  2. create a snapshot of that server with YATQA
  3. now tell your serveradmin of your targetserver you made a misstake and you want to have your backup imported to the server
  4. if successfull..-> you are able to edit the SQA servergroup and do everything you want to on your server
-> its a little bit of social engineering, too..

Next:

  • trying to do a SQL injection with the database backup :)
/edit: It's a lot easier than I thought.. If you don't change anything in the snapshot, you don't need to do anything.
I'll try to make a group with instance rights though :p
 
Last edited:

Zajao

Member
Jun 9, 2015
14
3
35
So, if I understood it correctly:
If I make my ATHP hoster to upload this "reimported" snapshot - I can get access not only to my virtual server - but to all of the virtual servers hosted on the machine?
Cause the full SQA grants access to all the virtual servers.
 

Supervisor

Administrator
Apr 27, 2015
1,863
2,546
335
Nope- that is the problem- it is like.. I'd add the SAQ group to your client- you still only have those rights on this virtual server, not on the whole instance..
BUT: you can edit the real SAQ group and any other Query groups etc
 

Supervisor

Administrator
Apr 27, 2015
1,863
2,546
335
Asphyxia is trying to do a sql injection with that backup- pretending that would work... you could do basically everything..
 

ehthe

Retired Staff
Contributor
Apr 26, 2015
1,029
896
216
I may not have fully understood the goal of you post, but if you just want to be serverquery admin you can do so just by adding yourself to the group with yaqta.
 

Zajao

Member
Jun 9, 2015
14
3
35
I tried this metod in my servers - and I got SQA rights to all virtual machines.
  1. I followed the steps in the article
  2. Then created a SQ-user from the existing client
  3. Then logged in to Yatqa with new credentials
  4. First it showed standard error message "If you are not serveradmin this is a normal restricrion by the server"
  5. Then I switched to my server (the big button)
  6. And from that point I was able to swicth back to serverlist and it worked:)
 

Zajao

Member
Jun 9, 2015
14
3
35
I has been able to get:
  • the VirtualServer List (IP : Port : MaxClients : ClientsOnline ) - but can't modify permissions on others servers
  • All the stats of the main TS server
  • A token to SQA group - but even with it - I can't reach other servers permissions

I didn't test switching on\off virtual servers on 3-d party server, but on mine I was able to do it
 
Last edited:

Supervisor

Administrator
Apr 27, 2015
1,863
2,546
335
I has been able to get:
  • the VirtualServer List (IP : Port : MaxClients : ClientsOnline ) - but can't modify permissions on others servers
  • All the stats of the main TS server
  • A token to SQA group - but even with it - I can't reach other servers permissions

I didn't test switching on\off virtual servers on 3-d party server, but on mine I was able to do it
I told you :p
You do have SQA-Access, but it is only valid for your server. So you cannot change any other servers :p
In order to do that you'd need to do SQL injection. Asphyxia wanted to try it.- If that works.. you could do everything
 
Top