Pentesting Notebook
Ctrlk
  • Offensive security
    • Tooling
    • Virtualisation
    • Active Directory
      • Domain Recon
      • Object Permissions
      • Privileged Groups
      • Group Policy
      • Kerberos
      • AD CS
      • MS SQL Servers
        • Enumeration
        • User mapping
        • Audit
        • MS SQL Impersonation
        • MS SQL Command Execution
          • xp_cmdshell
          • Object Linking and Embedding (OLE)
          • Custom Assemblies
          • Base64 encoded commands
        • MS SQL Lateral Movement
        • MS SQL Privilege Escalation
        • UNC Path Injection
        • SQLRecon
        • Custom SQL binary
        • impacket-mssqlclient
        • Metasploit Modules
        • Python in MSSQL
      • SCCM
      • Credential Theft
      • LAPS
      • Forest & Domain Trusts
      • Domain Dominance
      • User Impersonation
      • Lateral Movement
      • Relaying
      • Pivoting
      • Zerologon
      • BloodyAD
      • Expired Passwords
    • Infrastructure
    • OSEP: Checklist
    • AV Evasion
    • UAC Bypass
    • Applocker
    • Initial compromise
    • Privilege Escalation
    • Persistence
    • Data Protection API
    • Windows Script Host
    • Cobalt Strike
    • MetaSploit
    • Linux
    • macOS
    • SQLMap
    • Regex / sed
    • Cracking
    • Misc.
    • Visual Studio notes
  • Generic
    • Commands
    • Web
    • Fixing Errors
Powered by GitBook
On this page
  1. Offensive security
  2. Active Directory
  3. MS SQL Servers

MS SQL Command Execution

xp_cmdshellObject Linking and Embedding (OLE)Custom AssembliesBase64 encoded commands

Last updated 2 years ago