May 2017
Intermediate to advanced
416 pages
21h 33m
English
To use a specific username and password for MySQL, use the script argument username and password:
$ nmap -p1433 --script ms-sql-dump-hashes --script-args username=<user>,password=<password> <target>
If an SMB port is open, you can use it to run this script using pipes by setting the arguments mssql.instance-all or mssql.instance-name:
PORT STATE SERVICE 445/tcp open microsoft-ds Host script results: | ms-sql-empty-password: | [192.168.1.102\MSSQLSERVER] |_ sa:<empty> => Login Success | ms-sql-dump-hashes: | [192.168.1.102\MSSQLSERVER] | sa:0x020039AE3752898DF2D260F2D4DC7F09AB9E47BAB2EA3E1A472F 49520C26E206D0613E34E92BF929F53C463C5B7DED53738A7FC0790DD68 CF1565469207A50F98998C7E5C610 | ##MS_PolicyEventProcessingLogin##:0x0200BB8897EC23F14FC9FB8BFB0A ...
Read now
Unlock full access