Hacking SQL Server Procedures – Part 4: Enumerating Domain Accounts
netspi.com | blog | #active-directory | #privilege-escalation | #sql-injection | #powershell | #metasploit | #enumeration | #sql-server
Summary
With only the Public role, native SQL Server functions can enumerate AD users, groups, and computers; NetSPI ships PowerShell and Metasploit modules automating this via direct connections or SQLi.
- Published
- Collected
Skip to content