Microsoft SQL Server (MSSQL, port 1433) is the most productive database target in a Windows estate. It authenticates both SQL logins and Windows/domain accounts, its service runs as a privileged account that speaks NTLM, and it ships with stored procedures that run operating-system commands, reach other servers, and touch the filesystem. A single low-privilege login often chains to SYSTEM on the host or to Domain Admin.
Why MSSQL matters#
- It is AD-integrated: domain users can be database principals, and the service account's authentication can be coerced and relayed.
- It executes code:
xp_cmdshelland several other sinks give OS command execution as the service account. - It is networked to other servers through linked servers, so one instance pivots to many.
- Its privilege model (impersonation, database ownership, TRUSTWORTHY) has well-worn escalation chains from
publictosysadmin.
Pages#
- Enumeration: finding instances, versions, logins, databases, and the privileges you hold.
- Access: authenticating as a SQL or domain login and the roles that matter.
- Command execution: xp_cmdshell, OLE automation, and CLR for OS commands.
- Linked servers: querying and executing across server trust links.
- Impersonation: EXECUTE AS and TRUSTWORTHY ownership chains to sysadmin.
- Coercion and relay: xp_dirtree/xp_fileexist to capture or relay the service account.