December 2017
Intermediate to advanced
860 pages
16h 1m
English
We know that we have two users: sa and nipun. Let's supply one of them and try finding the other user credentials. We can achieve this with the help of the mssql_hashdump module. Let's check its working and investigate all other hashes on its successful completion:

As we can see clearly that, we have gained access to the password hashes for other accounts on the database server. We can now crack them using a third-party tool and can elevate or gain access to other databases and tables as well.
Read now
Unlock full access