NetExec MSSQL Query
Run an arbitrary SQL query against MSSQL via NetExec. Faster than firing up impacket-mssqlclient when you only need one statement (e.g. SELECT @@version, SELECT name FROM sys.databases).
- Tool
- nxc
- Category
- Enumeration / MSSQL
- Platform
- linux
- Requires
- password
- Protocols
- MSSQL
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc mssql <target> -u '<user>' -p '<password>' -q '<sql-query>'
Credential variants
The same attack using a different authentication material.
Local SQL Auth requires password
nxc mssql <target> -u 'sa' -p '<password>' --local-auth -q '<sql-query>'
Windows Auth requires password
nxc mssql <target> -u '<user>' -p '<password>' --windows-auth -q '<sql-query>'
Hash Auth requires NTLM hash
nxc mssql <target> -u '<user>' -H <nt-hash> -q '<sql-query>'
Examples
nxc mssql 10.10.10.10 -u sa -p 'Password123!' --local-auth -q 'SELECT @@version'
Tags
Related commands
- NetExec MSSQL enum_impersonate List every login the current user can EXECUTE AS (IMPERSONATE permission). The classic…
- NetExec MSSQL enum_logins List every SQL Server login (built-in sa, Windows-mapped accounts, contained DB users)…