MSSQL Enumeration
Overview
MSSQL Clients
SQL Server Management Studio (SSMS)
Alternative MSSQL Clients
Client
Description
Locating Impacket MSSQL Client
Default System Databases
Database
Description
Default Configuration
Initial Setup
Authentication Methods
Dangerous Settings
Setting
Risk Level
Description
Footprinting the Service
Comprehensive Nmap Scan
Example Nmap Output Analysis
Metasploit MSSQL Ping Scanner
Connecting with mssqlclient.py
Windows Authentication
Basic Database Enumeration
SQL Server Authentication
Advanced Enumeration
Database Information Gathering
System Information
HTB Academy Lab Questions
Question 1: Hostname Detection
Question 2: Non-Default Database Discovery
Enumeration Techniques
1. Service Detection
2. Authentication Testing
3. Database Analysis
Security Assessment
Common Vulnerabilities
Enumeration Checklist
Attack Vectors
1. Credential-based Access
2. Command Execution
3. Data Extraction
Tools and Techniques
Essential Tools
Defensive Measures
Security Best Practices
Last updated