MSSQL
Database commands
Comments
SELECT 1 -- comment
SELECT /*comment*/1Version
SELECT @@versionUsers
SELECT user_name();
SELECT system_user;
SELECT user;
SELECT loginame FROM master..sysprocesses WHERE spid = @@SPID
SELECT name FROM master..syslogins
EXEC sp_addlogin '<username>', '<password>'; -- priv
EXEC sp_droplogin '<username>'; -- priv
EXEC master.dbo.sp_addsrvrolemember '<username>', 'sysadmin'; -- priv
SELECT is_srvrolemember('sysadmin');
SELECT is_srvrolemember('sysadmin', '<usrername>');
SELECT name FROM master..syslogins WHERE sysadmin = '1'Privileges
Database info
Default tables
List tables
List columns
Filter table by column name
Access nth row
String operations
Control flow
Time delay
DNS and HTTP
Passwords
Vulnerabilities
RCE
Arbitrary file access
Last updated