Articles

Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

Full Version: Mssqlexec
passi
OK,

it's a program that allows to execute commands on Microsoft SQL Servers. It's not like SQLexec by sunx or the NetHacker one, mine has some more features. I wanted to write my own one smile.gif
It has the ability to run multiple commands. You don't have to enter command by command.

If you want more features, let me know. Some features are marked as 'not jet implemented'. If you think they would be useful, i will make them avaiable.

greetz, passiw

Btw: Please keep it private.
cyrixx
hey ho smile.gif
thx 4 your tool, gonna try it now! but there is an error on command "file/schließen" ...
andydis
nice, works a treat :-)
even a 2 year can hack now
Uli
Thanks smile.gif
daguilar01
when i tried to run it, it wanted comdlg32.ocx, so here it is for anyone else who needs it
[http://www.dll-files.com/dllindex/dll-files.shtml?comdlg32]

edit: one small suggestion would be to chagne the background color of output box and the drop down list that shows xp_cmdshell, lime and bright yellow isnt very clear
passi
*UPDATE*
Fixed version avaiable (scroll up).

Cyrixx: Error fixed smile.gif
Daguilar01: I don't understand what you mean ("lime and bright yellow isnt very clear ") so I changed color in yellow. I hope that's what you wanted me to do smile.gif
mortello
I think what he meant is that putting bright yellow on lime is quite difficult to see the difference....

I'll check the tool a little later

thanks
fre4k
very nice job dude ^^ I`ll going to test it wink.gif

xdccpt
been testing it and works great!

thanks for your work
Thom
Nice tool but it didnt work out for me:
"Connecting to 67.*.*.*
Fehler: "
Get that all the time, tested same IP in SQLexec.exe(by sunx? got an green apple as icon) and it worked there..
ehm
also muss sagen klasse programm mach weiter so ist echt geil das man mehrere commands benutzen kann! woohoo smile.gif

its a good programm keep the good work up dude!
DumpZ
Very nice tool your wrote mate, is it maybe possible to release the source so we can see how you builded this tool and maybe can help you with more features.

On my OS i missed a few OCX and DLL so for the people experencing that difficulty also i packed all the dlls and ocx files plus the exe in one rar
twistedps
yes, the source would be cool, i too wanted to find out how to send commands to the sql server, but instead i ended up using microsoft's free sql tool: osql.exe
it allows you to send commands to the sql server and comes free with sql, its small too.
passi
Dumpz: Thanks, so i got one thing less to do wink.gif

twisted: the code snipped that you need can be found in the programming area of this board (or use the search). maybe one day this boards gets a little bit more private and some absolute newbies get kicked. then i will post my source wink.gif
SURKIT007
Hello PassIW

Thanks for createing such a great tool with lots of advanced features its nice to see a bit of the ole SQL tools it makes a change.

P.S: Congratulations on this release

Best Regards

SURKIT
studnikov
Thanks for the source smile.gif Great work.
The Storm
nice work passiw :-)
o0oKARo0o
Excellent job, will test it later, thanks wink.gif
SeNe
nice tool m8, very usefull thanks
DumpZ
QUOTE (passiw @ Jul 10 2004, 09:25 AM)
Dumpz: Thanks, so i got one thing less to do wink.gif

twisted: the code snipped that you need can be found in the programming area of this board (or use the search). maybe one day this boards gets a little bit more private and some absolute newbies get kicked. then i will post my source wink.gif

Yeah i understand that very well.

They should make a private section were you only can access if your skilled enough, or something
Steve2017
NICE W0RK , THANX
Miserly
nice tool, thx for your work!
btw: you can enter many lines at once, can you also send them all together or will this return errors? (i don't hack, o i can't test it, just want to know it)

thx in advance!
passi
It normale case you enter as many lines as you want and then press the "Send" button. It won't return errors as far as i know.
Mrwh!P
wonderful, absolutely wonderful

Thanx dude.. I'm happy now laugh.gif
MaNiAx
very useful tool thanks for your contribution
WaTerBoy
SoOo Crazy,Nice design, work #1 !!! Good Job!!!! smile.gif
Jambo
well thx m8 i will test it later rolleyes.gif
PegHorse
Hello Passiw, i often use MSSQL, and i want to tell U a BIG THANKS smile.gif
I'll try it =)
Terminal
VEry nice and much better than sqlexec smile.gif .
passi
It still seems to be used by much of you, if you want i can make a newer version with all the features you want. yust say what you want in new features and (maybe) bugfixes smile.gif
Terminal
How about brute force?
Or u can also integrate Thcsql exploit that gives u direct shell on port 31337 .
Comsec posted thcsql and some more in download section . or its attached .
Iltis
really nice tool passiw big thx and respect for this nice toy =)

@vicky why adding bruteforce to this tool? it would be useless and then it would really be a hackertool
for bruteforce attacks there are enough good tools for example sqlck.exe and sqlcl.exe
bruteforcetools should always be commandline tools and should't have a gui

(my english suckz ass today i know)

net_runner
interesting topic, thanks, im going to make mi tests
Thom
Still gives me same error as the one I posted at page 1, I DL'd the .rar from dumpz aswell, no changes...I would like to use this tool ohmy.gif
Tomjack2000
Thanx for sharing this with us !
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2005 Invision Power Services, Inc.