SQL01
has a link to SQL02
, and SQL02
, has a link to SQL03
, and SQL03
, has a link to PAYMENTS01
. It is now possible to execute commands from SQL01
on PAYMENTS01
using the linked server chain (/link:SQL02,SQL03,PAYMENTS01 /chain
). Credit to Azael Martin (n3rada).l
‘ and ‘i
‘ modules, and introduced context logic so module names can be the same across standard, impersonation, linked and chained execution./debug
), which will display various debugging information and all SQL queries that will be executed by a module, without executing them./verbose, /v
), which will display all SQL queries that will be executed during module execution./timeout, /t
), which takes an integer value for SQL server database connection timeout.links
module to include detailed information. Credit to Azael Martin (n3rada).whoami
module to include Windows principals and database users. Credit to Azael Martin (n3rada).impersonation
module to include Windows principals and database users. Credit to Azael Martin (n3rada).sqlspns
enumeration module. Credit to Azael Martin (n3rada)./enum:info
module./subsystem
argument to the olecmdexec
module, which accepts execution using the CmdExec
or PowerShell
OLE automation subsystems.AzureAD
authentication to EntraID
./host
or /h
flag is now supported using comma separated values./link
or /l
flag is now supported using comma separated values./lhost
to /link
.s
‘ modules and created the /s
, /sccm
switch for SCCM modules.DecryptCredentials
./enum
) module called info
which is able to used an unauthenticated context to obtain SQL server information, including instance name and TCP port using the UDP protocol.ModuleHandler.cs
to promote simplification and extensibility.Queries.cs
.EnumerationModules.cs
.FormatQuery.cs
.SccmModules.cs
.ModuleHandler.cs
to SqlModules.cs
.adsi
execution was not removing the LDAP server.adsi
, in favor of openquery/rpc./lhost
to /adsi
in in adsi
module./rhost
to /unc
in smb
module.CaptureHash.cs
and simplified logic.SetEnumerationType.cs
and simplified logic.Impersonation.cs
to Impersonate.cs
.OleCmdExec.cs
to OleAutomation.cs
.PrintUtils.cs
to Print.cs
.SQLServerInfo.cs
to Info.cs
.smb
module.info
module.info
module.garak checks if an LLM can be made to fail in a way we don't…
Vermilion is a simple and lightweight CLI tool designed for rapid collection, and optional exfiltration…
ADCFFS is a PowerShell script that can be used to exploit the AD CS container…
Tartufo will, by default, scan the entire history of a git repository for any text…
Loco is strongly inspired by Rails. If you know Rails and Rust, you'll feel at…
A data hoarder’s dream come true: bundle any web page into a single HTML file.…