SQL01
has a link to SQL02
, and SQL02
, has a link to SQL03
, and SQL03
, has a link to PAYMENTS01
. It is now possible to execute commands from SQL01
on PAYMENTS01
using the linked server chain (/link:SQL02,SQL03,PAYMENTS01 /chain
). Credit to Azael Martin (n3rada).l
‘ and ‘i
‘ modules, and introduced context logic so module names can be the same across standard, impersonation, linked and chained execution./debug
), which will display various debugging information and all SQL queries that will be executed by a module, without executing them./verbose, /v
), which will display all SQL queries that will be executed during module execution./timeout, /t
), which takes an integer value for SQL server database connection timeout.links
module to include detailed information. Credit to Azael Martin (n3rada).whoami
module to include Windows principals and database users. Credit to Azael Martin (n3rada).impersonation
module to include Windows principals and database users. Credit to Azael Martin (n3rada).sqlspns
enumeration module. Credit to Azael Martin (n3rada)./enum:info
module./subsystem
argument to the olecmdexec
module, which accepts execution using the CmdExec
or PowerShell
OLE automation subsystems.AzureAD
authentication to EntraID
./host
or /h
flag is now supported using comma separated values./link
or /l
flag is now supported using comma separated values./lhost
to /link
.s
‘ modules and created the /s
, /sccm
switch for SCCM modules.DecryptCredentials
./enum
) module called info
which is able to used an unauthenticated context to obtain SQL server information, including instance name and TCP port using the UDP protocol.ModuleHandler.cs
to promote simplification and extensibility.Queries.cs
.EnumerationModules.cs
.FormatQuery.cs
.SccmModules.cs
.ModuleHandler.cs
to SqlModules.cs
.adsi
execution was not removing the LDAP server.adsi
, in favor of openquery/rpc./lhost
to /adsi
in in adsi
module./rhost
to /unc
in smb
module.CaptureHash.cs
and simplified logic.SetEnumerationType.cs
and simplified logic.Impersonation.cs
to Impersonate.cs
.OleCmdExec.cs
to OleAutomation.cs
.PrintUtils.cs
to Print.cs
.SQLServerInfo.cs
to Info.cs
.smb
module.info
module.info
module.shadow-rs is a Windows kernel rootkit written in Rust, demonstrating advanced techniques for kernel manipulation…
Extract and execute a PE embedded within a PNG file using an LNK file. The…
Embark on the journey of becoming a certified Red Team professional with our definitive guide.…
This repository contains proof of concept exploits for CVE-2024-5836 and CVE-2024-6778, which are vulnerabilities within…
This took me like 4 days (+2 days for an update), but I got it…
MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection. Its foundation is…