Skip to main content

Service Detection


Connect

impacket-mssqlclient

sqsh


Brute-Force

Default credentials: sa / (blank or weak password).

Command Execution — xp_cmdshell

Enable xp_cmdshell

Execute Commands

Reverse Shell


File Read

OPENROWSET


Steal NTLM Hash

Force MSSQL to authenticate to attacker SMB:
Capture with Responder:

Linked Servers

Execute on Linked Server


Enumerate

Databases

Tables

Users

Password Hashes


Impersonation


Quick Reference