Author Topic: Locate and Attack Domain SQL Servers without Scanning  (Read 425 times)

0 Members and 1 Guest are viewing this topic.

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Locate and Attack Domain SQL Servers without Scanning
« on: June 11, 2014, 10:23:33 pm »
In short, the author uses a PowerShell script that uses Service Principal Name (SPN) records from Active Directory to identify and attack SQL Servers on Windows domains without having to perform discovery scanning.
https://www.netspi.com/blog/entryid/228/locate-and-attack-domain-sql-servers-without-scanning

Offline Nero

  • /dev/null
  • *
  • Posts: 11
  • Cookies: -39
    • View Profile
Re: Locate and Attack Domain SQL Servers without Scanning
« Reply #1 on: June 12, 2014, 03:18:49 am »
Lol if I'm understand what you are saying correctly, you could use a Google dork to list some vulnerable SQL files.

But I get what you mean. I'll try it later.
This is a Signature! Woot!

Offline luverose

  • /dev/null
  • *
  • Posts: 15
  • Cookies: 6
  • lalalala~
    • View Profile
Re: Locate and Attack Domain SQL Servers without Scanning
« Reply #2 on: June 12, 2014, 03:48:51 am »
I'm not get it
When I was young ,I asked my mom why I have to eat meal?when I noticed my brother have ate my meal ,I think I was so stupid!

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: Locate and Attack Domain SQL Servers without Scanning
« Reply #3 on: June 25, 2014, 11:43:43 am »
Fools, he didn't mean a crooked vulnerable sql database-files. The very intent of this is to dodge this and go straight for the domain server, can't be a better choice sometimes since some admins sluck at updating anything except the web server.

It isn't meant to be understood by the faint of heart, learn some assembly, parser some domain charset binaries then hook in an sql server command. tadar;;;

^don't understand that either.
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]