Running commands through the command shell on MS SQL servers
MS SQL servers have a stored procedure called xp_cmdshell
. This feature allows programmers to execute commands through the MS SQL server. Nmap helps us execute custom shell commands when this option is enabled.
This recipe shows how to run Windows commands through MS SQL servers by using Nmap.
How to do it...
Open your terminal and enter the following Nmap command:
$ nmap --script-args 'mssql.username="<user>",mssql.password=""' --script ms-sql-xp-cmdshell -p1433 <target>
The results will be included in the script output section:
PORT STATE SERVICE VERSION 1433/tcp open ms-sql-s Microsoft SQL Server 2011 11.00.1750.00 | ms-sql-xp-cmdshell: | [192.168.1.102:1433] | Command: net user | output | ====== | | User accounts for \\ | | ------------------------------------------------------------------------------- | Administrator cldrn Guest...