


A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.



mssql 终端连接工具|命令执行

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

CVE-2021-3262 - Blind SQL Injection in the editOEN parameter of TripSpark VEO Transportation / NovusEDU. Unauthenticated, internet-facing. Payloads,…

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053

PoC CVE

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Pull Request-like Review/Approval flow for database queries. For compliant but smooth Engineering access to production.

Collaborative Passwords Manager

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

Relational database brute force and post exploitation tool for MySQL and MSSQL