h00die
|
32a4436ecd
|
first round of spelling/grammar fixes
|
2017-08-24 21:38:44 -04:00 |
james
|
e642789674
|
Look for sp_execute_external_script in mssql_enum
sp_execute_external_script can be used to execute code in MSSQL.
MSSQL 2016+ can be configured to execute R code. MSSQL 2017 can
be configured to execute Python code.
Documentation:
https://docs.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/sp-execute-external-script-transact-sql
https://docs.microsoft.com/en-us/sql/advanced-analytics/tutorials/rtsql-using-r-code-in-transact-sql-quickstart
Interesting uses of sp_execute_external_script:
R - https://pastebin.com/zBDnzELT
Python - https://gist.github.com/james-otten/63389189ee73376268c5eb676946ada5
|
2017-08-16 21:40:03 -05:00 |
Brent Cook
|
6300758c46
|
use https for metaploit.com links
|
2017-07-24 06:26:21 -07:00 |
g0tmi1k
|
ef826b3f2c
|
OCD - print_good & print_error
|
2017-07-19 12:48:52 +01:00 |
g0tmi1k
|
df9b642746
|
More print_status -> print_good
|
2017-07-19 11:39:15 +01:00 |
g0tmi1k
|
b8d80d87f1
|
Remove last newline after class - Make @wvu-r7 happy
|
2017-07-19 11:19:49 +01:00 |
g0tmi1k
|
4720d1a31e
|
OCD fixes - Spaces
|
2017-07-14 08:46:59 +01:00 |
g0tmi1k
|
fd843f364b
|
Removed extra lines
|
2017-07-14 08:17:16 +01:00 |
William Vu
|
64452de06d
|
Fix msf/core and self.class msftidy warnings
Also fixed rex requires.
|
2017-05-03 15:44:51 -05:00 |
David Maloney
|
eb73a6914d
|
replace old rex::ui::text::table refs
everywhere we called the class we have now rewritten it
to use the new namespace
MS-1875
|
2016-08-10 13:30:09 -05:00 |
James Lee
|
1375600780
|
Land #6644, datastore validation on assignment
|
2016-03-17 11:16:12 -05:00 |
James Lee
|
c21bad78e8
|
Fix some more String defaults
|
2016-03-16 14:13:18 -05:00 |
Christian Mehlmauer
|
3123175ac7
|
use MetasploitModule as a class name
|
2016-03-08 14:02:44 +01:00 |
Brent Cook
|
f703fa21d6
|
Revert "change Metasploit3 class names"
This reverts commit 666ae14259 .
|
2016-03-07 13:19:55 -06:00 |
Christian Mehlmauer
|
666ae14259
|
change Metasploit3 class names
|
2016-03-07 09:56:58 +01:00 |
Brent Cook
|
c7c0e12bb3
|
remove various module hacks for the datastore defaults not preserving types
|
2016-03-05 23:11:39 -06:00 |
James Lee
|
8094eb631b
|
Do the same for aux modules
|
2016-02-01 16:06:34 -06:00 |
Jon Hart
|
3535cf3d18
|
Remove peer; included via HttpClient in lib/msf/core/exploit/mssql_sqli.rb
|
2015-12-24 07:51:12 -08:00 |
Brent Cook
|
dea0142da1
|
catch network exceptions
|
2015-10-02 18:26:37 -05:00 |
William Vu
|
55895c6305
|
Fix nil bug in mssql_idf
|
2015-10-02 18:20:06 -05:00 |
jvazquez-r7
|
e729185804
|
Land #5051, @nullbind's new options for mssql_enum_domain_accounts_sqli
|
2015-04-03 14:44:20 -05:00 |
jvazquez-r7
|
fe9fbfd157
|
Make calculations easier
|
2015-04-03 14:43:01 -05:00 |
root
|
4bd40fed7f
|
yard doc and comment corrections for auxiliary
|
2015-04-03 16:12:23 +05:00 |
nullbind
|
91aeef0a8a
|
added startrid and endrid
|
2015-04-01 10:09:13 -05:00 |
Scott Sutherland
|
00dbcc12ca
|
Removed imp_user var from escalate_privs func
|
2015-03-15 22:02:12 -07:00 |
nullbind
|
5bebabb005
|
fixed hardcoded username
|
2015-03-15 19:45:02 -05:00 |
Christian Mehlmauer
|
544f75e7be
|
fix invalid URI scheme, closes #4362
|
2014-12-11 23:34:10 +01:00 |
Spencer McIntyre
|
86ae104580
|
Land #4325, consistent mssql module names
|
2014-12-09 21:52:05 -05:00 |
sinn3r
|
87c83cbb1d
|
Another round of name corrections
|
2014-12-09 20:16:24 -06:00 |
sinn3r
|
bb8dfdb15f
|
Ensure consistency for mssql modules
|
2014-12-09 10:28:45 -06:00 |
sinn3r
|
4b06334455
|
Minor title change for mssql_enum_domain_accounts_sqli
We don't really do "-" for naming
Kind of stands up on a list
|
2014-12-05 11:42:08 -06:00 |
Tod Beardsley
|
79f2708a6e
|
Slight fixes to grammar/desc/whitespace
Note that the format_all_drives module had a pile of CRLFs that should
have been caught by msftidy. Not sure why it didn't.
|
2014-12-04 13:11:33 -06:00 |
jvazquez-r7
|
5f4760c58e
|
Print final results in a table
|
2014-11-25 14:01:29 -06:00 |
jvazquez-r7
|
d998d97aaa
|
Refactor build_user_sid
|
2014-11-25 13:58:47 -06:00 |
jvazquez-r7
|
aad860a310
|
Make conditional easier
|
2014-11-25 13:54:08 -06:00 |
jvazquez-r7
|
ba57bc55b0
|
Don't report service
|
2014-11-25 13:52:22 -06:00 |
jvazquez-r7
|
059b0e91da
|
Don't report service
* The mssql could be in a third host, not rhost
|
2014-11-25 13:50:42 -06:00 |
jvazquez-r7
|
b467bda2d6
|
Reuse local variable
|
2014-11-25 13:49:24 -06:00 |
jvazquez-r7
|
31a84ef6ff
|
Make ternary operator more readable
|
2014-11-25 13:44:50 -06:00 |
jvazquez-r7
|
be566e5ad3
|
Use a lower fuzz number by default
|
2014-11-25 13:42:47 -06:00 |
jvazquez-r7
|
cd43f83cd7
|
Delete unnecessary comments
* No need to comment every step, just relevant
comments to undrestad code.
|
2014-11-25 13:40:57 -06:00 |
jvazquez-r7
|
f93dbc6deb
|
Use the target domain name
|
2014-11-25 13:36:48 -06:00 |
jvazquez-r7
|
7c87603b0e
|
Add progress information
|
2014-11-25 13:23:36 -06:00 |
jvazquez-r7
|
8e5b37ea6e
|
Fix reporting
|
2014-11-25 13:20:31 -06:00 |
jvazquez-r7
|
93539ae4c6
|
Use shorter variable name
|
2014-11-25 13:04:31 -06:00 |
jvazquez-r7
|
271f982f34
|
Use peer
|
2014-11-25 13:03:48 -06:00 |
jvazquez-r7
|
c549508abb
|
Use vprint
|
2014-11-25 13:03:18 -06:00 |
jvazquez-r7
|
249fb79a21
|
Fix print_* calls
|
2014-11-25 13:02:53 -06:00 |
jvazquez-r7
|
87cfd7c321
|
Dont use disconnect
|
2014-11-25 13:00:53 -06:00 |
jvazquez-r7
|
fb8372f505
|
Fix metadata
|
2014-11-25 12:59:11 -06:00 |