> For the complete documentation index, see [llms.txt](https://darkcybe.gitbook.io/darkcybe/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://darkcybe.gitbook.io/darkcybe/offensive-security-operations/penetration-testing/techniques/technology-focused/network-protocols-and-services/databases/port-1433-1434-mssql.md).

# Port 1433/1434 - MSSQL

## MSSQL

Microsoft SQL Server (MSSQL) often exposes two ports:

1. 1433 - Used by clients to interact with the database
2. 1434 - Used to list available instances (a Server can run multiple instances on high ports)

Default credentials are often set to `sa:sa`, which sa equivalent to Sysadmin.

### MSSQL Scanning and Enumeration

| Tool | Script/Module | Auth | MITRE ATT\&CK Tactic | Command                                    |
| ---- | ------------- | ---- | -------------------- | ------------------------------------------ |
| MSF  | mssql\_enum   | ?    | Reconnaissance       |                                            |
| MSF  | mssql\_ping   | ?    | Reconnaissance       |                                            |
| Nmap | ms-sql-info   | N    | Reconnaissance       | `sudo nmap -A -p 1433,1434 -n 10.10.10.10` |

### MSSQL Exploitation

| Tool | Script/Module                                                    | Auth | MITRE ATT\&CK Tactic                       | Command |
| ---- | ---------------------------------------------------------------- | ---- | ------------------------------------------ | ------- |
| MSF  | <p>mssql\_escalate\_dbowner<br>mssql\_escalate\_escalate\_as</p> | Y    | Privilege Escalation                       |         |
| MSF  | mssql\_hashdump                                                  | Y    | Credential Access                          |         |
| MSF  | mssql\_idf                                                       | Y    | Discovery                                  |         |
| MSF  | mssql\_local\_auth\_bypass                                       | Y    | <p>Persistence<br>Privilege Escalation</p> |         |
| MSF  | mssql\_ntlm\_stealer                                             | Y    | Credential Access                          |         |
| MSF  | mssql\_payload                                                   | Y    | Execution                                  |         |
| MSF  | mssql\_sql\_file                                                 | Y    | Execution                                  |         |

### MSSQL Database Interaction

the `mssqlclient.py` python tool that comes pre-installed on Kali Linux as part of the Impacket suite, can be used to interact with a remote MSSQL server.

{% code overflow="wrap" %}

```bash
# Connecting to a Remote MSSQL Server (Requires Database selection, Domain, Username, Password, and IP address entry.)
mssqlclient.py -db %DATABASE% -windows-auth %DOMAIN%/%USERNAME%:%PASSWORD%@%IP%

# Database Enumeration
SELECT * from %TABLE% # Show all stored data under a select table
SELECT * FROM %DATABASE%.INFORMATION_SCHEMA.TABLES; # Show tables under a select database

# Exploitation
CREATE LOGIN &USERNAME% WITH PASSWORD = '&PASSWORD%' # Create a new user and assign sysadmin privileges
sp_addsrvrolemember '%USERNAME%', 'sysadmin'
```

{% endcode %}
