Skills Assessment
Scenario
Phase 1: Discovery
Finding the Injection Point
Testing for Time-based SQLi
';IF(1=1) WAITFOR DELAY '0:0:10';--Phase 2: Database Enumeration
Oracle Script
Step 1: Database Name
Step 2: Table Count
Step 3: Table Names
Step 4: Column Names (users table)
Step 5: Row Count
Step 6: Extract Admin Credentials
Phase 3: Crack Password Hash
Phase 4: Second SQLi β RCE
Login as Admin
Find Second Injection
Test Time-based SQLi
Enable xp_cmdshell
Get Reverse Shell
Setup & Execute
Read Flag
Phase 5: Capture NetNTLM Hash
Start Responder
Trigger SMB Authentication
Send via SQLi
Capture Hash
Crack Hash
Attack Chain Summary
Techniques Used
Technique
Phase
Key Learnings
Last updated