Privilege Escalation
Initial Foothold
Default passwords
>> Get-SQLInstanceDomain | Invoke-SQLAuditDefaultLoginPw
or
>> Get-SQLInstanceDomain | Get-SQLServerLoginDefaultPw
Get-SQLInstanceScanUDP | Invoke-SQLAuditWeakLoginPw –> Start the attack from unauthenticated user perspective.
Get-SQLInstanceDomain | Invoke-SQLAuditWeakLoginPw –> Start the attack from domain user perspective.>> Get-SQLInstanceScanUDP | Get-SQLConnectionTestThreaded –Username username –Password password (manually)
or
>> Get-SQLInstanceDomain | Get-SQLConnectionTest
or
>> Get-SQLInstanceLocal | Get-SQLConnectionTest MITM
To Sysadmin
Blind SQL Login Enumeration
Impersonation
Database Links
UNC Path Injection
OS Command Execution
Last updated