Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
SQLRecon — 一个专为攻击性侦察和后期利用而设计的C# MS SQL工具包。 | Kitploit
工具/GitHubGitHub/skahwah/sqlrecon
侦察漏洞利用信息收集后渗透利用渗透测试身份验证红队数据库安全
GitHubskahwah/sqlrecon

SQLRecon

一个专为攻击性侦察和后期利用而设计的C# MS SQL工具包。

查看仓库
814129583个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
 
[![licence badge]][licence] 
[![wiki Badge]][wiki] 
[![stars badge]][stars] 
[![forks badge]][forks] 
[![issues badge]][issues] 

[licence badge]:https://img.shields.io/badge/License-BSD_3--Clause-blue.svg
[stars badge]:https://img.shields.io/github/stars/skahwah/SQLRecon.svg
[forks badge]:https://img.shields.io/github/forks/skahwah/SQLRecon.svg
[issues badge]:https://img.shields.io/github/issues/skahwah/SQLRecon.svg
[wiki badge]:https://img.shields.io/badge/SQLRecon-Wiki-green.svg

[licence]:https://raw.githubusercontent.com/skahwah/SQLRecon/main/LICENSE
[stars]:https://github.com/skahwah/SQLRecon/stargazers
[forks]:https://github.com/skahwah/SQLRecon/network
[issues]:https://github.com/skahwah/SQLRecon/issues
[wiki]:https://github.com/skahwah/SQLRecon/wiki

# SQLRecon

<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/5013/99bf48def961883bb073770c7a033a300b7f22b0da39f3fd30ad0e0da30b9da2.png">
</p>

SQLRecon 是一款专为攻击性侦察和后渗透阶段设计的 Microsoft SQL Server 工具集。如需详细了解每个技术的使用方法,请参考<a href="https://github.com/skahwah/SQLRecon/wiki">维基</a>。

您可以从 [releases](https://github.com/skahwah/SQLRecon/releases) 页面下载 SQLRecon 的副本。也可以自行编译解决方案——克隆仓库、双击解决方案文件并生成即可,过程简单直接。

针对防御者,我们还提供了<a href="https://github.com/skahwah/SQLRecon/wiki/9.-Prevention,-Detection-and-Mitigation-Guidance">预防、检测与缓解指南</a>。

欢迎阅读我在 <a href="https://securityintelligence.com/posts/databases-beware-abusing-microsoft-sql-server-with-sqlrecon/">IBM Security Intelligence</a> 网站上的博文。如果您更喜欢视频,可以观看我在 <a href="https://www.youtube.com/watch?v=LsYSePobFWA">Black Hat</a> 的演讲。

# 枚举模块

枚举模块不需要提供身份验证提供者。这些模块必须传递到枚举模块标志(`/e:, /enum:`)中。维基页面有关于使用<a href="https://github.com/skahwah/SQLRecon/wiki/1.-Enumeration">枚举模块</a>的详细信息。```
Info    - Show information about the SQL server.
          /h:, /host    -> SQL server hostname or IP. Multiple hosts supported.
          /port:        -> (OPTIONAL) Defaults to 1434 (UDP).
          /t:, timeout: -> (OPTIONAL) Defaults to 3s.

SqlSpns - Use the current user token to enumerate the AD domain for MSSQL SPNs.
          /d:, /domain: -> (OPTIONAL) NETBIOS name or FQDN of domain.
```
# 认证提供者

SQLRecon 支持多种认证提供者(`/a:, /auth:`),以便与 Microsoft SQL Server 进行交互。```
WinToken   - Use the current users token to authenticate against the SQL database
             /h:, /host:     -> SQL server hostname or IP

WinDomain  - Use AD credentials to authenticate against the SQL database
             /h:, /host:     -> SQL server hostname or IP. Multiple hosts supported.
             /d:, /domain:   -> NETBIOS name or FQDN of domain.
             /u:, /username: -> Username for domain user.
             /p:, /password: -> Password for domain user.

Local      - Use local SQL credentials to authenticate against the SQL database
             /h:, /host:     -> SQL server hostname or IP. Multiple hosts supported.
             /u:, /username: -> Username for local SQL user.
             /p:, /password: -> Password for local SQL user.

EntraID    - Use Azure EntraID credentials to authenticate against the Azure SQL database
             /h:, /host:     -> SQL server hostname or IP. Multiple hosts supported.
             /d:, /domain:   -> FQDN of domain (DOMAIN.COM).
             /u:, /username: -> Username for domain user.
             /p:, /password: -> Password for domain user.

AzureLocal - Use local SQL credentials to authenticate against the Azure SQL database
             /h:, /host:     -> SQL server hostname or IP. Multiple hosts supported.
             /u:, /username: -> Username for local SQL user.
             /p:, /password: -> Password for local SQL user.

Pth        - Authenticate using an NT hash (pass-the-hash) over raw TDS/NTLM. Elevated privileges or SeImpersonate is not required.
             /h:, /host:     -> SQL server hostname or IP. Multiple hosts supported.
             /d:, /domain:   -> NETBIOS domain name.
             /u:, /username: -> Domain username.
             /hash:          -> NT hash (32 hex chars, 8846f7eaee8fb117ad06bdd830b7586c) or LM:NT format.
```
### 身份验证提供程序 - 附加详情

- **主机**:`/h:` 或 `host:` 标志是必需的,允许指定一个或多个 SQL 服务器。如果要针对多个 SQL 服务器执行模块,请用逗号分隔主机,例如 `/h:SQL01,10.10.10.2,SQL03`。
- **数据库**:默认情况下,SQLRecon 连接到 `master` 数据库,但可以通过 `数据库` (`/database:`) 标志提供自定义数据库名称来更改此项。
- **调试**:`/debug` 标志是可选的,它会显示模块将要执行的所有 SQL 查询,而不会在远程主机上实际执行它们。相关示例可以在 <a href="https://github.com/skahwah/SQLRecon/wiki">wiki</a> 中找到。
- **端口**:在某些情况下,Microsoft SQL Server 可能未在标准 TCP 端口上侦听。例如 Microsoft SQL Server 故障转移群集或动态 TCP 端口。默认情况下,SQLRecon 通过 TCP 端口 `1433` 连接数据库,但可以通过 `/port:` 标志更改此项。
- **超时**:默认 SQL 数据库连接时间为 `3` 秒,但可以通过提供超时值(`/t:` 或 `/timeout:`)更改此项,该值表示终止连接尝试前的秒数。
- **详细输出**:`/v` 或 `/verbose` 标志是可选的,它会在远程主机上执行模块之前显示该模块将要执行的所有 SQL 查询。相关示例可以在 <a href="https://github.com/skahwah/SQLRecon/wiki">wiki</a> 中找到。

请注意,`EntraID` 身份验证提供程序要求 Azure Active Directory 身份验证库(ADAL)或 Microsoft 身份验证库(MSAL)存在于运行 SQLRecon 的系统上。这是用于 Azure EntraID 身份验证和授权功能的。

# SQL 模块

SQL 模块针对一个或多个 Microsoft SQL server 实例执行。这些模块必须通过模块标志(`/m:` 或 `/module:`)传入。

| 模块名称 | 描述 | 模拟 | 链接执行 | 链接链执行 | 需要特权上下文 |
| ----------- | ----------- | ------------- | ---------------- | ---------------------- | --------------------------- |
| `AuditStatus` | 检查是否启用了 SQL 审计。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `CheckRpc` | 获取链接服务器列表及其 RPC 状态。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Databases` | 显示所有数据库。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Impersonate` | 枚举可以被模拟的用户账户。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Info` | 显示有关 SQL 服务器的信息。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Links` | 枚举链接的 SQL 服务器。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Users` | 显示哪些用户账户和组可以针对数据库进行身份验证。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Whoami` | 显示您的权限。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Query /c:QUERY` | 执行 SQL 查询。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Smb /unc:UNC_PATH` | 捕获 NetNTLMv2 哈希。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Columns /db:DATABASE /table:TABLE` | 显示指定数据库和表中的所有列。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Rows /db:DATABASE /table:TABLE` | 显示指定数据库表中的行数。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Search /keyword:KEYWORD` | 在连接到数据库的指定表中搜索列名。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `Tables /db:DATABASE` | 显示指定数据库中的所有表。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :negative_squared_cross_mark: |
| `EnableRpc /rhost:LINKED_HOST` | 在链接服务器上启用 RPC 和 RPC OUT。 | :white_check_mark: | :x: | :x: | :heavy_check_mark: |
| `EnableClr` | 启用 CLR 集成。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `EnableOle` | 启用 OLE 自动化过程。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `EnableXp` | 启用 xp_cmdshell。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `DisableRpc /rhost:LINKED_HOST` | 在链接服务器上禁用 RPC 和 RPC OUT。 | :white_check_mark: | :x: | :x: | :heavy_check_mark: |
| `DisableClr` | 禁用 CLR 集成。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `DisableOle` | 禁用 OLE 自动化过程。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `DisableXp` | 禁用 xp_cmdshell。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `AgentStatus` | 显示 SQL 代理是否正在运行并获取代理作业。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `AgentCmd /c:COMMAND /subsystem:(可选) /proxy:(可选)` | 使用代理作业执行系统命令。可选择通过 `/subsystem:` 指定子系统,默认为 'PowerShell'。可选择通过 `/proxy:` 指定 SQL 代理代理账户。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `Adsi /adsi:SERVER_NAME /lport:LOCAL_PORT` | 从链接的 ADSI 服务器获取明文 ADSI 凭据。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `Clr /dll:DLL /function:FUNCTION` | 在自定义存储过程中加载并执行 .NET 程序集。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `CredentialObjects` | 从 sys.credentials 获取凭据对象。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `OleCmd /c:COMMAND /subsystem:(可选)` | 使用 OLE 自动化过程执行系统命令。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `Proxies` | 获取 SQL 代理代理信息。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |
| `XpCmd /c:COMMAND` | 使用 xp_cmdshell 执行系统命令。 | :white_check_mark: | :white_check_mark: | :white_check_mark: | :heavy_check_mark: |

### SQL 模块 - 标准

`/h:` 或 `host:` 标志是必需的,允许指定一个或多个 SQL 服务器。如果要针对多个 SQL 服务器执行模块,请用逗号分隔主机,例如 `/h:SQL01,10.10.10.2,SQL03`。

Wiki 详细介绍了如何使用每个支持在 <a href="https://github.com/skahwah/SQLRecon/wiki/3.-Standard-Modules">SQL Server</a> 的一个或多个实例上执行的模块。

### SQL 模块 - 模拟

模拟模块在一个或多个 Microsoft SQL server 实例上以被模拟的 SQL 用户身份执行。所有模拟模块具有以下最低要求:
- 必须指定一个模拟用户(`/i:` 或 `/iuser:`)。
- 必须指定一个支持模拟的模块(`/m:` 或 `/module:`)。

Wiki 详细介绍了如何使用每个支持通过 <a href="https://github.com/skahwah/SQLRecon/wiki/4.-Impersonation-Modules">模拟</a> 执行的模块。

### SQL 模块 - 链接

链接模块在一个或多个链接的 Microsoft SQL server 实例上执行。所有链接模块具有以下最低要求:
- 必须指定一个链接的 SQL 服务器(`/l:` 或 `/link:`)。链接标志允许一个或多个链接的 SQL 服务器。例如,如果 SQL01 链接到 SQL02,并且 SQL01 链接到 DB04,您可以用逗号分隔链接的主机,模块将在每个链接的 SQL 服务器上执行,例如 `/l:SQL02,DB04`。
- 必须指定一个支持链接执行的模块(`/m:` 或 `/module:`)。

Wiki 详细介绍了如何使用每个支持在 <a href="https://github.com/skahwah/SQLRecon/wiki/5.-Linked-Modules">链接的 SQL Server</a> 的一个或多个实例上执行的模块。

### SQL 模块 - 链接链

链接链模块在链接服务器链中的最后一个 Microsoft SQL server 上执行。所有链接链模块具有以下最低要求:
- 必须在 `/l:` 或 `/link:` 标志中指定一个链接的 SQL 服务器链。如果 SQL01 链接到 SQL02,并且 SQL02 链接到 PAYMENTS01,并且您希望在 PAYMENTS01 上执行模块,则参数为 `/l:SQL02,PAYMENTS01`。
- 必须包含 `/chain` 标志才能针对提供的链接链中的最后一个 SQL 服务器执行模块。
- 必须指定一个支持链接链执行的模块(`/m:` 或 `/module:`)。

Wiki 详细介绍了如何使用每个支持在 <a href="https://github.com/skahwah/SQLRecon/wiki/6.-Linked-Chain-Modules">链接的 SQL 服务器链</a> 中提供的最后一个 SQL 服务器上执行的模块。

# SCCM 模块

SQLRecon 有几个模块可以帮助枚举和攻击 Microsoft System Center Configuration Manager (SCCM) 和 Microsoft Endpoint Configuration Manager (ECM)。SCCM 或 ECM 服务器需要在本地或远程公开 Microsoft SQL 数据库。

SCCM 模块必须通过 SCCM 模块标志(`/s:` 或 `/sccm:`)传入。

大多数 SCCM 模块可以在模拟的 SQL 用户(`/i:` 或 `/iuser:`)上下文中执行。

Wiki 详细介绍了如何针对 <a href="https://github.com/skahwah/SQLRecon/wiki/7.-SCCM-Modules">SCCM/ECM 数据库</a> 使用每个模块。

| 模块名称 | 描述 | 模拟 | 需要特权上下文 |
| ----------- | ----------- | ------------- | --------------------------- |
| `Users` | 显示所有 SCCM 用户。 | :white_check_mark: | :negative_squared_cross_mark: |
| `Sites` | 显示所有存储数据且具有数据的其他站点。 | :white_check_mark: | :negative_squared_cross_mark: |
| `Logons` | 显示所有关联的 SCCM 客户端以及最后登录的用户。 | :white_check_mark: | :negative_squared_cross_mark: |
| `Credentials` | 显示由 SCCM 存储的加密凭据。 | :white_check_mark: | :negative_squared_cross_mark: |
| `TaskList` | 显示所有任务序列,但不访问任务数据内容。 | :white_check_mark: | :negative_squared_cross_mark: |
| `TaskData` | 将所有任务序列解密为明文。 | :white_check_mark: | :negative_squared_cross_mark: |
| `DecryptCredentials` | 解密 SCCM 凭据 Blob。必须在 SCCM 服务器上以高完整性或 SYSTEM 进程执行。 | :x: | :heavy_check_mark: |
| `AddAdmin /user:DOMAIN\USERNAME /sid:SID` | 将提供的账户提升为 SCCM 中的 'Full Administrator'。 | :white_check_mark: | :heavy_check_mark: |
| `RemoveAdmin /user:ADMIN_ID /remove:STRING` | 移除用户的权限,或从 SCCM 数据库中完全移除用户。 | :white_check_mark: | :heavy_check_mark: |
| `ScriptData` | 返回所有配置在 SCCM 中运行的脚本。 | :white_check_mark: | :heavy_check_mark: |
| `CIData` | 返回所有配置为在 SCCM 中运行脚本的 CI。 | :white_check_mark: | :heavy_check_mark: |

<details>
<summary>SCCM 模块 - 附加详情</summary>

* `Users` 模块列出 `RBAC_Admins` 表中的所有用户。这些是配置为对 SCCM 具有某种级别访问权限的所有用户。
* `Sites` 模块列出 SCCM 数据库 `DPInfo` 表中存储数据的所有其他站点。这可以提供额外的攻击途径,因为不同的站点可以以不同的(不安全)方式配置。
* `Logons` 模块查询 `Computer_System_DATA` 表,以检索所有关联的 SCCM 客户端及其最后登录的用户。<b>注意:</b>默认情况下,该信息每周只更新一次,并非 100% 最新。使用 `/option:` 作为可选(非必需)参数来筛选 SCCM 客户端。
* `TaskList` 模块提供 SCCM 数据库中存储的所有任务序列列表,但不会访问实际的任务数据内容。
* `TaskData` 模块恢复 SCCM 数据库中存储的所有任务序列并将其解密为明文。任务序列可能包含用于将系统加入域、映射共享、运行命令等的凭据。
* `Credentials` 模块列出 SCCM 存储的用于各种功能的凭据。这些凭据无法远程解密,因为密钥存储在 SCCM 服务器上。但该模块提供了情报,判断是否有必要尝试获取密钥。
* `DecryptCredentials` 模块尝试解密恢复的 SCCM 凭据 Blob。此模块必须在 SCCM 服务器上以高完整性或 SYSTEM 进程运行。
* `AddAdmin` 模块将指定账户提升为 SCCM 中的 'Full Administrator'。如果目标用户已经是 SCCM 用户,则该模块将改为添加提升所需的新权限。提供了两个参数。如果希望将当前执行 SQLRecon 进程的用户添加为 SCCM 中的 'Full Administrator',则使用 `/user:current /sid:current`。如果希望将其他用户添加为 SCCM 中的 'Full Administrator',则指定其域用户名和完整 SID `/user:DOMAIN\USERNAME /sid:S-1-5-...`。此模块需要 sysadmin 或类似权限,因为需要写入 SCCM 数据库表。
* `RemoveAdmin` 模块移除用户的权限,方法是完全从 SCCM 数据库中删除新添加的用户。如果用户已以某种身份存在,则该模块仅移除通过写入权限表而添加到账户的三个角色。使用 `sAddAdmin` 命令输出中提供的参数运行此命令。此模块需要 sysadmin 或类似权限,因为需要写入 SCCM 数据库表。
</details>

# 扩展 SQLRecon

如果您有兴趣扩展 SQLRecon,请参考 <a href="https://github.com/skahwah/SQLRecon/wiki/8.-Contributing-and-Extending-SQLRecon">wiki</a> 中的贡献和扩展部分。

如果您有任何建议或想法,欢迎提交 [issue](https://github.com/skahwah/SQLRecon/issues)。

### 路线图

目标是持续改进 SQLRecon。以下列出了一些计划中的研究领域:

* 实现基于 NTLM 哈希的身份验证支持。
* 探索针对链接和链接链 SQL 服务器的 enablerpc/disablerpc 功能。

### 致谢

以下人员直接或间接地对 SQLRecon 的各个方面做出了贡献。

- Adam Chester [(xpn)](https://github.com/xpn)
- Andrew Smith [(jakxx)](https://github.com/jakxx)
- Azaël Martin [(n3rada)](https://github.com/n3rada)
- Crusher [(chryzsh)](https://github.com/chryzsh)
- Daniel Duggan [(rasta-mouse)](https://github.com/rasta-mouse)
- Dave Cossa [(G0ldenGunSec)](https://github.com/G0ldenGunSec)
- Dwight Hohnstein [(djhohnstein)](https://github.com/djhohnstein)
- Javier Balanza [(JBalanza)](https://github.com/JBalanza)
- Joshua Magri [(passthehashbrowns)](https://github.com/passthehashbrowns)

# 历史记录
<details>
<summary>v4.0</summary>

* 添加了 NTLM 传递哈希身份验证提供程序 (`/auth:pth`)。通过 PTHTdsConnection、NtlmHelper 和 PthState 实现了原始 TDS/NTLM 身份验证,因此所有模块无需明文凭据或提升权限即可工作。关键修复包括登录后的 ANSI 会话选项、多包 TDS 分割、并发 CLR 连接的 TCP 流死锁处理以及 OPENQUERY 括号表示法兼容性。
* 模拟模块中的错误修复。
* adsi 模块中的错误修复。
* ole 模块中的错误修复。
* `_linkedChainRpcQuery` 中的错误修复。
* 修复了长期存在的问题,即 `System.Byte[]` 从未正确转换并打印到控制台。
* 添加了 `credentialobjectss` 和 `proxies` 模块 (jakxx)。
* 更新了 README.md
* 更新了 Wiki
</details>

<details>
<summary>v3.12</summary>

* 为 `agentcmd` 添加了代理支持 (jakxx)。
* 解决了 `role` 枚举在链接链中无法正常工作的问题 (passthehashbrowns)。
* 解决了 `impersonate` 模块在链接链中无法正常工作的问题 (passthehashbrowns)。
* 解决了 `EnableRpc`/`DisableRpc` 在链接链中不可用的问题 (passthehashbrowns)。
* 解决了 `XpCmd` 模块在链接链中无法工作的问题,现在还支持输出 (passthehashbrowns)。
* 解决了包含 '.' 字符的链接服务器名称在 `EXEC AT` 查询中导致问题的问题,除非将其用括号括起来,但如果是 IP 地址或 FQDN 则会导致问题 (passthehashbrowns)。
* 对构造链接服务器链查询的逻辑进行了调整。现有逻辑使用递归,基本情况期望数组的第一个元素为 "0",但在开发需要迭代链接链的模块时会带来不符合直觉的行为,例如 .First 函数返回 "0"。已更新 `LinkedChainQuery` 函数,使其创建一个以 "0" 开头的新数组,然后在一个单独的函数(现称为 `LinkedChainQueryRecurse`)中调用现有逻辑 (passthehashbrowns)。
</details>

<details>
<summary>v3.11</summary>

* 添加了在为高可用性(具有活动 + 被动服务器)配置的站点中解密存储凭据的功能。
</details>

<details>
<summary>v3.10</summary>

* 修复了 `impersonate` 模块中处理 sysadmin 情况的问题 (n3rada)。
* 实现了两个新的 SCCM 模块 `scriptdata` 和 `cidata` (G0ldenGunSec)。
* 优化了 CLR DLL 加载和执行时间 (chryzsh)。
* 创建了 `auditstatus` 模块来检查 SQL 审计是否已启用 (chryzsh)。
* 更新了测试用例。
* 更新了 README。
* 更新了 Wiki。
</details>

<details>
<summary>v3.9</summary>

* 在 `whoami` 模块中添加了用户有权访问的数据库 (JBalanza)。
* 修复了 `adsi` 模块中 LDAP 服务器无需添加到 msdb 数据库的问题,现在创建的函数也会被正确删除。
* 修复了包含 AT 语句的 RPC 查询在目标服务器上失败的问题,如果提供的主机名是 FQDN。
* 更新了 README。
* 更新了 Wiki。
</details>

<details>
<summary>v3.8</summary>

* 添加了在 SQL Server 2016 及以下版本上执行 CLR 程序集的逻辑。适用于 clr 模块。支持在所有上下文中执行。
* 添加了在 SQL Server 2016 及以下版本上加载 LDAP 服务器 CLR 程序集的逻辑。适用于 adsi 模块。支持在所有上下文中执行。
* 更新了 README。
* 更新了 Wiki。
</details>

<details>
<summary>v3.7</summary>* 完全重构代码库。
* 更新文档(代码注释、README 和 wiki)。
* 支持针对关联的 SQL 服务器链执行。例如,如果 `SQL01` 链接到 `SQL02`,`SQL02` 链接到 `SQL03`,`SQL03` 链接到 `PAYMENTS01`,现在可以使用链接服务器链从 `SQL01` 对 `PAYMENTS01` 执行命令(`/link:SQL02,SQL03,PAYMENTS01 /chain`)。感谢 Azaël Martin (n3rada)。
* 移除了 '`l`' 和 '`i`' 模块,并引入了上下文逻辑,使得模块名称在标准、模拟、链接和链式执行中可以保持一致。
* 为所有链接模块添加了链支持。
* 添加了调试支持(`/debug`),将显示各种调试信息以及模块将要执行的所有 SQL 查询,而不实际执行。
* 添加了详细输出(`/verbose, /v`),将显示模块执行期间将要执行的所有 SQL 查询。
* 添加了超时设置(`/timeout, /t`),接受一个整数值用于 SQL 服务器数据库连接超时。
* 改进了 `links` 模块,包含详细信息。感谢 Azaël Martin (n3rada)。
* 改进了 `whoami` 模块,包含 Windows 主体和数据库用户。感谢 Azaël Martin (n3rada)。
* 改进了 `impersonation` 模块,包含 Windows 主体和数据库用户。感谢 Azaël Martin (n3rada)。
* 为 `sqlspns` 枚举模块添加了 IP 地址检索功能。感谢 Azaël Martin (n3rada)。
* 标准化控制台输出为 Markdown 格式(如适用)。感谢 Azaël Martin (n3rada)。
* 为 `/enum:info` 模块添加了 DNS 支持。
* 为 `olecmdexec` 模块添加了可选的 `/subsystem` 参数,支持使用 `CmdExec` 或 `PowerShell` OLE 自动化子系统执行。
* 更新测试框架以反映 CLI 变更和新模块。
* 将 `AzureAD` 认证更改为 `EntraID`。
</details>

<details>
<summary>v3.6</summary>

* 现在支持在 `/host` 或 `/h` 标志中使用逗号分隔的值来针对多个 SQL 服务器执行。
* 现在支持在 `/link` 或 `/l` 标志中使用逗号分隔的值来针对多个关联的 SQL 服务器执行。
* 将 `/lhost` 更改为 `/link`。
* 移除了 '`s`' 模块,并为 SCCM 模块创建了 `/s`、`/sccm` 开关。
* 为所有 SCCM 模块添加了模拟支持,但 `DecryptCredentials` 除外。
* 添加了一个新的枚举(`/enum`)模块 `info`,它能够使用未认证的上下文通过 UDP 协议获取 SQL 服务器信息,包括实例名称和 TCP 端口。
* 将参数逻辑移至 `ModuleHandler.cs` 中的单独方法,以促进简化和可扩展性。
* 将所有 SQL 查询移至 `Queries.cs`。
* 创建了 `EnumerationModules.cs`。
* 创建了 `FormatQuery.cs`。
* 创建了 `SccmModules.cs`。
* 将 `ModuleHandler.cs` 重命名为 `SqlModules.cs`。
</details>

<details>
<summary>v3.5</summary>

* 修复了链接 `adsi` 执行未移除 LDAP 服务器的错误。
* 移除了链接 `adsi` 中的代理作业执行,改用 openquery/rpc。
* 将 `adsi` 模块中的 `/lhost` 更改为 `/adsi`。
* 将 `smb` 模块中的 `/rhost` 更改为 `/unc`。
* 移除了 `CaptureHash.cs` 并简化了逻辑。
* 移除了 `SetEnumerationType.cs` 并简化了逻辑。
* 将 `Impersonation.cs` 重命名为 `Impersonate.cs`。
* 将 `OleCmdExec.cs` 重命名为 `OleAutomation.cs`。
* 将 `PrintUtils.cs` 重命名为 `Print.cs`。
* 将 `SQLServerInfo.cs` 重命名为 `Info.cs`。
</details>

<details>
<summary>v3.4</summary>

* 为 `smb` 模块添加了模拟支持。
* 为 `info` 模块添加了模拟支持。
* 为 `info` 模块添加了链接支持。
</details>

<details>
<summary>v3.3</summary>

* 创建了 `rows`、`iRows` 和 `lRows` 模块。
* 更新了 `sLogons`,包含可选过滤器。
* 修复了 `xp_cmdshell` 模块未将命令输出打印到控制台的错误。
* 清理了帮助菜单。
</details>

<details>
<summary>v3.2</summary>

* 命令行参数解析重构。
* 使用新示例更新了 README、测试用例和 wiki。
* 重新设计了枚举和基于认证的参数解析。
* 创建了 `SetEnumerationType.cs`。
* 将枚举模块 `domain` 更改为 `SqlSpns`。
</details>

<details>
<summary>v3.1</summary>

* 将 `SetAuthenticationType.cs` 的构造函数更改为名为 `EvaluateAuthenticationType` 的新方法。
* 在 `SetAuthenticationType.cs` 中创建了 `CreateSqlConnectionObject`,扩展了 SQLRecon 以支持多个同时的 SQL 连接对象。
* 创建了 `ADSI.cs`,集成了如[此处](https://www.tarlogic.com/blog/linked-servers-adsi-passwords/)所述的 ADSI 凭据攻击。
* 创建了 `adsi`、`iAdsi` 和 `lAdsi` 模块。
* 创建了 `lLinks` 和 `iLinks` 模块。
* 使用新示例更新了 README、测试用例和 wiki。
</details>

<details>
<summary>v3.0</summary>

* 实现了对不存在的模拟用户的错误检查。
* 创建了 `ExecuteImpersonationQuery` 和 `ExecuteImpersonationCustomQuery`。
* 删除了 `Impersonate.cs`。
* 添加了 `checkRpc` 模块。
* 添加了 `iCheckRpc` 模块。
* 添加了 `lCheckRpc` 模块。
* 重新设计了 SCCM 模块。
* 重新设计了 SCCM 参数解析。
* 帮助菜单中的命令使用驼峰命名以便阅读。
* 使用新模块更新了测试。
</details>

<details>
<summary>v2.9</summary>

* 将 `EnableDisable.cs` 重命名为 `ConfigureOptions.cs`。
* 重构了高级选项配置。
* 在调用 `ExecuteLinkedCustomQueryRpcExec` 的地方实现了 RPC 错误检查。
</details>

<details>
<summary>v2.8</summary>

* 创建了 `PrintUtils.cs`,实现了一个用于标准化输出的打印类。
* 将 `TablePrinter` 从 `Help.cs` 移动到 `PrintUtils.cs`。
* 使用 `PrintUtils` 类标准化了所有控制台输出的打印格式。
* 更改了类和类变量的访问修饰符。
* 为以下模块添加了结果是否为空的检查:
    * `query`
    * `search`
    * `tables`
    * `lColumns`
    * `lQuery`
    * `lSearch`
    * `lTables`
    * `iColumns`
    * `iQuery`
    * `iSearch`
* 针对所有认证提供者和模块进行了重要的可靠性和功能测试。
</details>

<details>
<summary>v2.7</summary>

* 将 `Azure` 认证更改为 `AzureAD`。
* 创建了 `AzureLocal` 认证。
* 添加了 `disableRpc` 模块。
* 添加了 `enableRpc` 模块。
* 添加了 `iEnableRpc` 模块。
* 添加了 `iDisableRpc` 模块。
* 移除了 `lEnableRpc` 模块。
* 移除了 `lDisableRpc` 模块。
* 使用新模块更新了测试。
</details>

<details>
<summary>v2.6.1</summary>

* `lAgentCmd` 错误修复。
* 修复了 `clr`、`iClr` 和 `lClr` 的稳定性,在创建存储过程时使用 `SqlCommand.ExecuteNonQuery`。
* 修复了 `lClr` 中未移除已创建程序集或存储过程的错误。
</details>

<details>
<summary>v2.6</summary>

* 添加了 `columns` 模块。
* 添加了 `iColumns` 模块。
* 添加了 `iDatabases` 模块。
* 添加了 `iSearch` 模块。
* 添加了 `iTables` 模块。
* 添加了 `lColumns` 模块。
* 添加了 `lSearch` 模块。
</details>

<details>
<summary>v2.5</summary>

* SCCM 模块中的各种错误修复。
* 使用表格组织了帮助菜单。
* 改进了 `ExecuteLinkedCustomQueryRpcExec` 提供的输出。
* 改进了代码注释。
* 改进了命令执行函数中方法名称的一致性。
* 通过更好地使用面向对象编程改进了模块化。
* 将自定义 SQL 服务器端口标志更改为 `x`。
* 将 `Random.cs` 移入 `utilities` 目录。
* 标准化了打印风格,使其在所有模块中更加一致。
* 创建了标准、模拟和链接测试框架。
</details>

<details>
<summary>v2.4</summary>

* 将 `Windows` 认证更改为 `WinToken`。
* 创建了 `WinDomain` 认证,它使用 AD 域用户名和密码通过模拟进行认证。查看 `Impersonation.cs`。
* 重新设计了 `ArgumentLogic.cs`、`SQLAuthentication.cs` 和 `ModuleHandler.cs` 中的参数解析和处理。
* `ModuleHandler.cs` 不再使用庞大的 if/else if/else 语句来执行模块。而是使用反射来调用与命令模块名称匹配的方法。
* 添加了 `commands` 目录,其中包含程序中使用的全局变量。
* 将所有认证提供者合并到 `SQLAuthentication.cs` 中。
* 将参数解析从 `Program.cs` 移至 `ArgumentLogic.cs`。
* 移除了 `authentication` 目录。
* 更改了代码风格,以更好地遵循 [Microsoft 的 C#/.NET 代码风格指南](https://learn.microsoft.com/en-us/dotnet/csharp/fundamentals/coding-style/coding-conventions)。
* 将 `Help.cs` 从方法更改为构造函数。
* 将 `CaptureHash.cs` 从方法更改为构造函数。
* 将 `Impersonate.cs` 从方法更改为构造函数。
* 完全重构了代码库。
</details>

<details>
<summary>v2.3</summary>

* 添加了 SCCM 功能。
* 添加了 SCCM 模块,可以通过 `sccm` 命令执行。
* 修复了在关联 SQL 服务器上检查 RPC 状态的问题。
* 添加了通过 HTTP/S 下载 .NET 程序集的功能。
</details>

<details>
<summary>v2.2</summary>

* 扩展了在 `roles`、`iRoles` 和 `lRoles` 模块中查询的角色。
* 创建了 `users`、`iUsers` 和 `lUsers` 模块。
* 修复了 `clr` 和 `iClr` 模块中哈希未被 `sp_drop_trusted_assembly` 移除的问题。
* 创建了 `lAgentCmd` 模块。
* 创建了 `lClr` 模块。
</details>

<details>
<summary>v2.1.6</summary>

* 添加了 `info` 模块。
* 帮助菜单中的修正。
* 解决了 `Local` 和 `Azure` 认证中强制参数的问题。
</details>

<details>
<summary>v2.1.5</summary>

* 添加了枚举域 SPN 的模块(`-e domain`)。
</details>

<details>
<summary>v2.1.4</summary>

* 修复了小的字符串格式化问题。
</details>

<details>
<summary>v2.1.3</summary>

* 在 `Windows` 和 `Local` 认证模式中添加了 `-r` 标志,以便提供非标准 TCP 端口。
</details>

<details>
<summary>v2.1.2</summary>

* 改进了空连接字符串的逻辑。
</details>

<details>
<summary>v2.1.1</summary>

* 从 `TestAuthentication.cs` 中移除了 `Environment.Exit`。
</details>

<details>
<summary>v2.1</summary>

* 创建了 `AgentJobs.cs`。
* 创建了 `agentStatus`。
* 创建了 `iAgentStatus`。
* 创建了 `lAgentStatus`。
* 创建了 `agentCmd`。
* 创建了 `iAgentCmd`。
</details>

<details>
<summary>v2.0</summary>

* 创建了 `clr`。
* 创建了 `iEnableClr`。
* 创建了 `iDisableClr`。
* 创建了 `iClr`。
* 创建了 `iWhoami`。
* 创建了 `iMapped`。
* 创建了 `iRoles`。
* 创建了 `lEnableRpc`。
* 创建了 `lDisableRpc`。
* 创建了 `lWhoami`。
* 创建了 `lEnableXp`。
* 创建了 `lDisableXp`。
* 创建了 `lEnableOle`。
* 创建了 `lDisableOle`。
* 创建了 `lEnableClr`。
* 创建了 `lDisableClr`。
* 创建了 `lXpCmd`。
* 创建了 `lXpOle`。
* 创建了 `Random.cs`。
* 创建了 `EnableDisable.cs`。
* 为 `clr` 实现了随机生成的程序集名称。
* 为 `ole` 实现了随机生成的变量和方法名称。
* 将 `mapped` 和 `roles` 模块合并到 `whoami` 中。
* 将 `lMapped` 和 `lRoles` 模块合并到 `lWhoami` 中。
* 将 `iMapped` 和 `iRoles` 模块合并到 `iWhoami` 中。
* 完全重构了代码库。
</details>

<details>
<summary>v1.2</summary>

* 创建了 `lSmb` 模块。
* 创建了 `lWhoami` 模块。
* 创建了 `lRoles` 模块。
</details>

<details>
<summary>v1.1</summary>

* 修复了 `oleCmd` 模块。
* 修复了 `iOleCmd` 模块。
* 修复了 `lDatabases` 模块。
* 修复了 `lTables` 模块。
* 清理了代码库。
* 修正了帮助菜单中的不一致之处。
</details>
下载工具