Authentication

Testing credentials

You can use two methods to authenticate to the MSSQL: windows or local (default: windows). To use local auth, add the following flag --local-auth

Windows auth

  1. With SMB port open

#~ cme mssql 10.10.10.52 -u james -p '[email protected][email protected]!'
  1. With SMB port close, add the flag -d DOMAIN

#~ cme mssql 10.10.10.52 -u james -p '[email protected][email protected]!' -d HTB

Expected Results:

MSSQL 10.10.10.52 1433 MANTIS [+] HTB\james:[email protected][email protected]!

Local auth

#~ cme mssql 10.10.10.52 -u admin -p '[email protected][email protected]!' --local-auth

Expected Results:

MSSQL 10.10.10.52 1433 None [+] admin:[email protected][email protected]! (Pwn3d!)

Specify Ports

#~ cme mssql 10.10.10.52 -u admin -p '[email protected][email protected]!' --port 1434