MSSQL

Database commands

Comments

SELECT 1 -- comment
SELECT /*comment*/1

Version

SELECT @@version

Users

SELECT user_name();
SELECT system_user;
SELECT user;
SELECT loginame FROM master..sysprocesses WHERE spid = @@SPID
SELECT name FROM master..syslogins
EXEC sp_addlogin '<username>', '<password>'; -- priv
EXEC sp_droplogin '<username>'; -- priv
EXEC master.dbo.sp_addsrvrolemember '<username>', 'sysadmin'; -- priv
SELECT is_srvrolemember('sysadmin');
SELECT is_srvrolemember('sysadmin', '<usrername>');
SELECT name FROM master..syslogins WHERE sysadmin = '1'

Privileges

Database info

Default tables

List tables

List columns

Filter table by column name

Access nth row

String operations

Control flow

Time delay

DNS and HTTP

Passwords

Format: SHA1-based

Vulnerabilities

RCE

To reactivate the console in case the command fails:

Arbitrary file access

Last updated