SQL Server default login
By default the SA user is NOT enabled. Administrators might enable it during the installation and choose a weak password.
Last updated
By default the SA user is NOT enabled. Administrators might enable it during the installation and choose a weak password.
Last updated
Login to WEB01
as the Administrator
user with password Welcome01!
.
2. Open "Microsoft SQL Server Management Studio"
3. Login with the Administrator
user using Windows Authentication.
4. Expand the "Security" and "Logins" folders. Right click "sa" and select "Properties". Make sure "Enforce password policy" is unchecked and fill in the password sa
twice.
One of the default users (not enabled by default) for SQL Server is the SA user. Administrators might enable it during the installation and choose a weak password, such as the username.
Check if the MSSQL server on WEB01
can be contacted from our Kali machine:
2. Paste the following passwords in passwords.txt
to spray with:
3. Run Crackmapexec to connect to the MSSQL service running on WEB01
and passwordspray the passwords till there is a succesfull login:
We got a succesfull login as the sa
user with the password sa
.
4. Run Crackmapexec again with the password sa and use the -q
flag to try to execute the query select @@version
to retrieve the MSSQL version.
5. Connect to the database using mssql-cli.
Check the executing commands page under SQL Server Attacks to learn to execute cmd commands:
Make sure the password policy is enforced for all users on the SQL server.
Dont use the sa account, this account is well to known and attackers will attempt to brute-force it.