mssql-hax0r v0.9 – Multi-purpose MS-SQL injection script
Darknet spilled these bits on August 10th 2007 @ 4:54 am

mssql-hax0r v0.9 is a Multi-purpose MS-SQL injection attack tool for advanced Microsoft SQL Server exploitation. Three modes of operation are currently available: info (Information Gathering), dump (Record Dump), and brute (Brute Force).

You may need to tweak the code a bit to make it fit your needs (i.e. modifying the injection string and/or the language used by the RDBMS).

TODO (v1.0):

  • fix italian language support (test platform needed)
  • info mode: add logins target (master..sysxlogins) [name,dbname,password]
  • brute mode: automatic login grabbing feature?
  • info mode: add sys target (xtype=’S')?
  • info mode: implement better types/keys dumping
  • add a command execution mode via master..xp_cmdshell?
  • add a privileged testing mode for post-auth vulnerabilities

It’s a fairly early version, I’ve been watching it since v0.1 – it’s a little more polished now but it’s still definitely a tool for more advanced users.

I’m sure some of you will find it useful.

Grab it here:

mssql-hax0r

Tags:  ,  ,  ,  ,  ,  ,  ,  ,  ,  ,  

rss Subscribe to Darknet RSS Feed rss

| 7,282 views |

comments are closed
  1. August 10th, 2007 | 8:10 pm

    I wonder if you can add this script to the metasploit framework. First you’d have to convert the Bash script to Ruby. hmm

  2. J Random
    August 12th, 2007 | 5:40 pm

    Why is there no email on this page? How can I reach you?

  3. August 13th, 2007 | 8:54 am

    TRDQ: You could, but it’d be quite a bit of work.

    J Random: What do you think the Contact Darknet link is for?

  4. Daniel
    August 13th, 2007 | 9:30 am

    hmm any project with the word hax0r in the name is born out of boredom and pure blackhat glee

  5. J Random
    August 13th, 2007 | 12:10 pm

    Hehe, oopsie

  6. Sandeep Nain
    August 16th, 2007 | 12:54 am

    good tool in making… im sur eit will be a good tool once its mature enough

  7. Sandeep Nain
    August 31st, 2007 | 2:40 am

    Very good tool for information gathwring and record dumping…
    Really cool tool in security toolbox..

Sitemap - ShaolinTiger - DigiSniper - Digital Photography
Shutter Asia Photography Forum - We Ate This