MSSQL
MSSQL comments
-- comment goes here
/* comment goes here */MSSQL User
SELECT CURRENT_USERMSSQL version
SELECT @@versionMSSQL database name
SELECT DB_NAME()MSSQL List databases
SELECT name FROM master..sysdatabases;
SELECT DB_NAME(N); — for N = 0, 1, 2, …MSSQL List columns
MSSQL List tables
MSSQL Extract user/password
MSSQL Union Based
MSSQL Error based
MSSQL Blind based
MSSQL Time based
MSSQL Stacked Query
MSSQL Read file
MSSQL Command execution
MSSQL Out of band
MSSQL DNS exfiltration
MSSQL UNC Path
MSSQL Make user DBA (DB admin)
MSSQL Trusted Links
Manual exploitation
References
Last updated