Microsoft SQL (MSSQL)
1) Nmap Scan
nmap --script ms-sql-info,ms-sql-empty-password,ms-sql-xp-cmdshell,ms-sql-config,ms-sql-ntlm-info,ms-sql-tables,ms-sql-hasdbaccess,ms-sql-dac,ms-sql-dump-hashes --script-args mssql.instance-port=1433,mssql.username=sa,mssql.password=,mssql.instance-name=MSSQLSERVER -sV -p 1433 IPnmap --script ms-sql-info,ms-sql-empty-password,ms-sql-xp-cmdshell,ms-sql-config,ms-sql-ntlm-info,ms-sql-tables,ms-sql-hasdbaccess,ms-sql-dac,ms-sql-dump-hashes --script-args mssql.instance-port=1433,mssql.username=<username>,mssql.password=<password>,mssql.instance-name=<instance_name> -sV -p 1433 IP2) Netexec
netexec mssql -d domain.local -u USERNAME -p PASSWORD -x "whoami" IPnetexec mssql -d domain.local -u USERNAME -p PASSWORD -x "SELECT name FROM master.dbo.sysdatabases;" IP3) Authentication
sqsh -S IP -U USERNAME -P PASSWORDsqsh -S IP -U domain\\USERNAME -P PASSWORD -D DATABASE4) Exploitation
5) Impersonation (Windows AD)
6) Database Usage
Last updated