MSSQL-Attacks for red teamers (The Final Exploitation)



MSSQL-Attacks for red teamers (The Final Exploitation)

MSSQL-Attacks for red teamers (The Final Exploitation)

#MSSQL service #attacks are very common during an #ActiveDirectory security #assessment . In this series I will be guiding to building and exploiting MSSQL Service within an active directory env.

Its the final video for the series where exploitation of every MSSQL vulnerabilities is covered using my own written tool MSSQL-Attacker for red teamer.

================= Chapters =================

00:00 – appreciation
01:25 – Speaker Intro
02:50 – Agenda
04:01 – The Essentials (MSSQL)
05:40 – The Essentials (AD)
07:25 – The Essentials (Connection)
10:24 – The Essentials (SMB)
18:56 – UNC PATH injection
26:49 – Impersonate SA
34:38 – Impersonate DBO
42:19 – Linked Server and RCE
47:51 – Like/Share/Subs..