Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Hacking SQL Server Stored Procedures – Part 2: User Impersonation

Summary

This lab walkthrough shows how the IMPERSONATE privilege lets low-privileged SQL Server logins escalate to sysadmin through EXECUTE AS configurations, automated with Metasploit and PowerShell.
Published
Collected

original ↗