Dark Mode

Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Ridter/PySQLTools

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

10 Commits

Repository files navigation

PySQLTools

SharpSQLTools PythonBan Ben ,Fang Bian Zai Mei windowsJi Qi Huo Dai Li Chang Jing Xia Shi Yong .

Dui Yu LinkXiang Guan Cao Zuo Mei Zuo Xiang Guan Ce Shi . You Wen Ti Ke Yi Ti Issue.

Shi Yong

Zhi Chi WindowsJi Mi Ma Ren Zheng

WindowsRen Zheng Fang Shi Wei :

python PySQLTools.py localhost/administrator:'password'@10.211.55.251 -windows-auth -debug

Zhang Hao Mi Ma Ren Zheng Fang Shi Wei :

python PySQLTools.py sa:'password'@10.211.55.251

Ru Guo Peng Dao Yi Xia Cuo Wu :

[-] [('SSL routines', '', 'unsafe legacy renegotiation disabled')]

Ke Tian Jia OPENSSLPei Zhi Wen Jian Lai Jia Zai ,Ru :

OPENSSL_CONF=openssl.conf python PySQLTools.py sa:'password'@10.211.55.251

Zhi Chi Gong Neng Ru Xia :

enable_xp_cmdshell - you know what it means
disable_xp_cmdshell - you know what it means
xp_cmdshell {cmd} - executes cmd using xp_cmdshell
sp_oacreate {cmd} - executes cmd using sp_oacreate
xp_dirtree {path} - executes xp_dirtree on the path
sp_start_job {cmd} - executes cmd using the sql server agent (blind)
enable_ole - you know what it means
disable_ole - you know what it means
upload {local} {remote} - upload a local file to a remote path (OLE required)
download {remote} {local} - download a remote file to a local path (OLE required)
enable_clr - you know what it means
disable_clr - you know what it means
install_clr - create assembly and procedure
uninstall_clr - drop clr
clr_pwd - print current directory by clr
clr_ls {directory} - list files by clr
clr_cd {directory} - change directory by clr
clr_ps - list process by clr
clr_netstat - netstat by clr
clr_ping {host} - ping by clr
clr_cat {file} - view file contents by clr
clr_rm {file} - delete file by clr
clr_exec {cmd} - for example: clr_exec whoami;clr_exec -p c:.exe;clr_exec -p c:\cmd.exe -a /c whoami
clr_efspotato {cmd} - exec by EfsPotato like clr_exec
clr_badpotato {cmd} - exec by BadPotato like clr_exec
clr_godpotato {cmd} - exec by GodPotato like clr_exec
clr_combine {remotefile} - When the upload module cannot call CMD to perform copy to merge files
clr_dumplsass {path} - dumplsass by clr
clr_rdp - check RDP port and Enable RDP
clr_getav - get anti-virus software on this machin by clr
clr_adduser {user} {pass} - add user by clr
clr_download {url} {path} - download file from url by clr
clr_scloader {shellcode} - shellcode.bin
clr_assembly {prog} {args} - execute-assembly.
clr_assembly_sc {shellcode} - assembly shellcode created by donut.
use_link {link} - linked server to use (set use_link localhost to go back to local or use_link .. to get back one step)
enum_db - enum databases
enum_links - enum linked servers
enum_impersonate - check logins that can be impersonate
enum_logins - enum login users
enum_users - enum current db users
enum_owner - enum db owner
exec_as_user {user} - impersonate with execute as user
exec_as_login {login} - impersonate with execute as login
! {cmd} - executes a local shell cmd
show_query - show query
mask_query - mask query

Geng Xin

2023/07/27

Tian Jia Liao Zhi Xing assemblyDe Gong Neng ,Tong Guo Jia Zai shellcodeDe Fang Shi Shi Xian ,Zai linuxShang Ke Wan Mei Yun Xing :

Zai Qi Ta Ping Tai Shang ,Xu Yao Shi Yong dockerDe donutSheng Cheng shellcode,Zai Shi Yong clr_assembly_scJin Xing Jia Zai Zhi Xing .

CLR

CLRYuan Ma Jian :MSSQL_CLR

Can Kao :

1, https://github.com/uknowsec/SharpSQLTools
2, https://github.com/ShutdownRepo/impacket/blob/getST/examples/mssqlclient.py

About

MssqlLi Yong Gong Ju

Resources

Readme

Stars

Watchers

Forks

Releases

No releases published

Packages

Contributors

Languages