xsspresso
xsspresso
Tags/ MSSQL

MSSQL

5 writeups tagged with MSSQL

ADMediumWindows

HTB — Signed

MSSQL with xp_cmdshell for initial RCE. Active Directory certificate abuse (ADCS) to impersonate Domain Admin.

#AD#MSSQL#ADCS
Nov 20, 2025HackTheBox
ADMediumWindows

HTB — NanoCorp

MSSQL enumeration with credential discovery, followed by Active Directory privilege escalation through ACL misconfigurations.

#MSSQL#AD#ACL Abuse
Nov 8, 2025HackTheBox
MiscMediumWindows

HTB — Hercules

Windows machine leveraging MSSQL linked server abuse and xp_cmdshell to gain initial foothold, then DPAPI credential decryption for escalation.

#MSSQL#Linked Servers#xp_cmdshell
Oct 20, 2025HackTheBox
ADMediumWindows

HTB — EscapeTwo

MSSQL with xp_cmdshell after credential spraying. ADCS ESC4 template modification for certificate impersonation to gain Domain Admin.

#AD#MSSQL#ADCS
Jan 13, 2025HackTheBox
ADMediumWindows

HTB — Escape

MSSQL Silver Ticket attack via SPN enumeration. Responder captures NTLMv2 hash from SQL query, certificate auth for Domain Admin.

#AD#MSSQL#Silver Ticket
Nov 19, 2024HackTheBox