MSSQL
MSSQL Database Authentication and Dumping
Commands:
impacket-mssqlclient -k DOMAIN.LOCAL -no-passimpacket-mssqlclient -windows-auth DOMAIN\\USERNAME@TARGET_IPimpacket-mssqlclient USERNAME@TARGET_IP DATABASE COMMANDS
SELECT name FROM sys.databases; SELECT TABLE_NAME,TABLE_SCHEMA FROM targetdb.INFORMATION_SCHEMA.TABLES; SELECT * FROM targetdb.dbo.targettable GIVE ACCESS TO A DATABASE WITH SYSADMIN PRIVILEGES
LINKED DATABASES ABUSE
COMMAND EXECUTION WITH XP_CMDSHELL
MSSQL Tool: PowerUpSQL
Enumerating from the network without domain session
Enumerating from inside the domain
MSSQL Abuse
MSSQL RCE
MSSQL Trusted Links
Last updated