Open bdamele opened 12 years ago
Proposed enhancements to MSSQL enumeration:
1) Add support for linked server enumeration:
--links
SELECT srvname FROM master..sysservers
2) Add support for schema enumeration on linked servers:
-S _LINKEDSERVER_ --dbs
SELECT name FROM _LINKEDSERVER_.master.sys.databases
3) Add support for sql shell on linked servers.
More info: https://blog.netspi.com/how-to-hack-database-links-in-sql-server/
Thoughts?
@lukapusic doable... though, only MsSQL as I can see. So, introducing too many new options for just one DBMS is a coding anti-pattern in sqlmap
+1 for this. I've had lots of success pillaging through DB links.
FWIW, database links aren't limited to just MSSQL. Oracle has them as well. https://docs.oracle.com/html/E25494_01/ds_concepts002.htm
Identify linked/cluster DBMS servers when possible (e.g. MSSQL)