Microsoft SQL Server

Microsoft SQL Server (MSSQL, port 1433) is the most productive database target in a Windows estate. It authenticates both SQL logins and Windows/domain accounts, its service runs as a privileged account that speaks NTLM, and it ships with stored procedures that run operating-system commands, reach other servers, and touch the filesystem. A single low-privilege login often chains to SYSTEM on the host or to Domain Admin.

Why MSSQL matters#

  • It is AD-integrated: domain users can be database principals, and the service account's authentication can be coerced and relayed.
  • It executes code: xp_cmdshell and several other sinks give OS command execution as the service account.
  • It is networked to other servers through linked servers, so one instance pivots to many.
  • Its privilege model (impersonation, database ownership, TRUSTWORTHY) has well-worn escalation chains from public to sysadmin.

Pages#

  • Enumeration: finding instances, versions, logins, databases, and the privileges you hold.
  • Access: authenticating as a SQL or domain login and the roles that matter.
  • Command execution: xp_cmdshell, OLE automation, and CLR for OS commands.
  • Linked servers: querying and executing across server trust links.
  • Impersonation: EXECUTE AS and TRUSTWORTHY ownership chains to sysadmin.
  • Coercion and relay: xp_dirtree/xp_fileexist to capture or relay the service account.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more