CrackMapExec Test_connection (mssql)
This page contains detailed information about how to use the test_connection CME module while using the mssql protocol. For list of all CrackMapExec modules, visit the CrackMapExec Module Library.
Description
This module executes the Test-Connection PowerShell cmdlet to check if the specified HOST is reachable using ICMP ping.
The test_connection module is OPSEC safe. This means that it doesn't touch the disk and therefore shouldn't trigger any alarms.
Supported Protocols
- mssql
- smb
Module Source Code
Authors
Module Options
As you can see below, the test_connection module has one option:
# cme mssql -M test_connection --options
[*] test_connection module options:
HOST Host to ping
The HOST option is required! Make sure you set it when using this module.
Module Usage
This is how to use the test_connection module while using the mssql protocol:
Syntax:
# cme mssql <TARGET[s]> -u <USERNAME> -p <PASSWORD> -d <DOMAIN> -M test_connection -o HOST=<host>
Admin user:
# cme mssql 10.0.5.1 -u sa -p P@ss123 -d . -M test_connection -o HOST=10.0.6.11
# cme mssql 10.0.5.1 -u sa -p P@ss123 --local-auth -M test_connection -o HOST=10.0.6.11
Normal user:
# cme mssql 10.0.5.1 -u dbuser -p P@ss123 -d target.corp -M test_connection -o HOST=10.0.6.11
CrackMapExec also supports passing the hash, so you can specify NTLM hash instead of a password:
# cme mssql 10.0.5.1 -u sa -H 432b022dc22aa5afe884e986b8383ff2 -d . -M test_connection -o HOST=10.0.6.11
# cme mssql 10.0.5.1 -u dbuser -H 432b022dc22aa5afe884e986b8383ff2 -d target.corp -M test_connection -o HOST=10.0.6.11
The test_connection module can be also used against multiple hosts. Here's how to run it against multiple hosts:# cme mssql target_list.txt -u sa -p P@ss123 -d . -M test_connection -o HOST=10.0.6.11
# cme mssql 10.0.5.0/24 -u sa -p P@ss123 -d . -M test_connection -o HOST=10.0.6.11
# cme mssql 10.0.5.1-100 -u sa -p P@ss123 -d . -M test_connection -o HOST=10.0.6.11
References
Version
This page has been created based on CrackMapExec version 5.1.7dev.
Visit CrackMapExec Module Library for more modules.