
mssqli-duet
SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

Windows privilege escalation tool exploiting SeImpersonate privileges via Named Pipe impersonation, supporting multiple execution methods…

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053


CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

Relational database brute force and post exploitation tool for MySQL and MSSQL

Offensive MSSQL toolkit written in Python, based off SQLRecon

mssql 终端连接工具|命令执行


PoC CVE

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.