BackTrack 5R1 Cracking MS SQLServer

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
2,417
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Oct 5, 2011

Using Backtrack 5R1 and metasploit we exploit a MSSQL instance on a Server 2003 box. We brute force the SA account, and with that, gain administrative access on the machine. While the demonstration is done on Server 2003 with SQLServer 2000, it can also be done with SQLServer 2005 and SQLServer Express on XP/Vista/7/Server 2008.

With the induction of SQL Server 2008, the SA account is deprecated and replaced with SYSADMIN. While this account is disabled by default, some of your IT guys are lazy and re-enable it to reminence on the glory days.

To sum it up, that bajillion character super admin password you have on your server is worthless unless you have an equally impressive database account password.

This video also demonstrates hash-passing (because sometimes we're just too lazy to crack the hash to find out the real password) which we'll use to regain access to the system as root at a later date.

Category:

Education

Tags:

License:

Standard YouTube License

  • likes, 0 dislikes

Link to this comment:

Share to:
see all

All Comments (2)

Sign In or Sign Up now to post a comment!
  • good vidoa  thanks !

  • Another excellent video

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more