
Un toolkit C# MS SQL progettato per ricognizione offensiva e post-sfruttamento.
SQLRecon è un toolkit per Microsoft SQL Server progettato per ricognizione offensiva e post-sfruttamento. Per informazioni dettagliate su come utilizzare ogni tecnica, fare riferimento alla wiki.
Puoi scaricare una copia di SQLRecon dalla pagina releases. In alternativa, sentiti libero di compilare la soluzione da solo. Dovrebbe essere semplice come clonare il repository, fare doppio clic sul file della soluzione e compilare.
Guida alla prevenzione, rilevamento e mitigazione è stata fornita anche per tutti voi difensori.
Dai un'occhiata al mio post sul blog sul sito IBM Security Intelligence. Se preferisci i video, dai un'occhiata alla mia presentazione al Black Hat.
I moduli di enumerazione non richiedono che venga fornito un provider di autenticazione. Questi moduli devono essere passati al flag del modulo di enumerazione (/e:, /enum:). La wiki ha dettagli sull'uso dei moduli di enumerazione.```
Info - Show information about the SQL server.
/h:, /host -> SQL server hostname or IP. Multiple hosts supported.
/port: -> (OPTIONAL) Defaults to 1434 (UDP).
/t:, timeout: -> (OPTIONAL) Defaults to 3s.
SqlSpns - Use the current user token to enumerate the AD domain for MSSQL SPNs. /d:, /domain: -> (OPTIONAL) NETBIOS name or FQDN of domain.
# Fornitori di Autenticazione
SQLRecon supporta un insieme diversificato di fornitori di autenticazione (`/a:, /auth:`) per consentire l'interazione con un Microsoft SQL Server.```
WinToken - Use the current users token to authenticate against the SQL database
/h:, /host: -> SQL server hostname or IP
WinDomain - Use AD credentials to authenticate against the SQL database
/h:, /host: -> SQL server hostname or IP. Multiple hosts supported.
/d:, /domain: -> NETBIOS name or FQDN of domain.
/u:, /username: -> Username for domain user.
/p:, /password: -> Password for domain user.
Local - Use local SQL credentials to authenticate against the SQL database
/h:, /host: -> SQL server hostname or IP. Multiple hosts supported.
/u:, /username: -> Username for local SQL user.
/p:, /password: -> Password for local SQL user.
EntraID - Use Azure EntraID credentials to authenticate against the Azure SQL database
/h:, /host: -> SQL server hostname or IP. Multiple hosts supported.
/d:, /domain: -> FQDN of domain (DOMAIN.COM).
/u:, /username: -> Username for domain user.
/p:, /password: -> Password for domain user.
AzureLocal - Use local SQL credentials to authenticate against the Azure SQL database
/h:, /host: -> SQL server hostname or IP. Multiple hosts supported.
/u:, /username: -> Username for local SQL user.
/p:, /password: -> Password for local SQL user.
Pth - Authenticate using an NT hash (pass-the-hash) over raw TDS/NTLM. Elevated privileges or SeImpersonate is not required.
/h:, /host: -> SQL server hostname or IP. Multiple hosts supported.
/d:, /domain: -> NETBIOS domain name.
/u:, /username: -> Domain username.
/hash: -> NT hash (32 hex chars, 8846f7eaee8fb117ad06bdd830b7586c) or LM:NT format.
/h:, host:) è obbligatorio e permette di specificare uno o più server SQL. Se si desidera eseguire un modulo su più server SQL, separare gli host con una virgola, ad esempio /h:SQL01,10.10.10.2,SQL03.master per impostazione predefinita, tuttavia è possibile modificarlo fornendo un nome di database personalizzato tramite il flag database (/database:)./debug è opzionale e mostra tutte le query SQL eseguite da un modulo, senza effettivamente eseguirle sul/i host remoto/i. Un esempio è disponibile nel wiki.1433 per impostazione predefinita, tuttavia è possibile modificarla utilizzando il flag /port:.3 secondi, tuttavia è possibile modificare questo valore fornendo un timeout (/t:, /timeout:) che corrisponde al numero di secondi prima di terminare il tentativo di connessione./v, /verbose è opzionale e mostra tutte le query SQL eseguite da un modulo prima di eseguirle sul/i host remoto/i. Un esempio è disponibile nel wiki.Si noti che il provider di autenticazione EntraID richiede che la libreria di autenticazione Azure Active Directory (ADAL) o la libreria di autenticazione Microsoft (MSAL) sia presente nel sistema in cui viene eseguito SQLRecon. Questo è per la funzionalità di autenticazione e autorizzazione di Azure EntraID.
I moduli SQL vengono eseguiti su una o più istanze di Microsoft SQL Server. Questi moduli devono essere passati al flag del modulo (/m:, /module:).