mssqlclient.py: Interacting with Microsoft SQL Servers

mssqlclient.py is a Python-based tool from the Impacket library, designed for interacting with Microsoft SQL Server instances. It’s commonly used in penetration testing and red teaming to authenticate, execute queries, upload/download files, and perform various administrative tasks against SQL Servers, especially in Windows environments.

Prerequisite: Impacket Library

To use mssqlclient.py, you need to have the Impacket library installed. You can typically install it via pip:

pip install impacket

Or clone the repository and install from there for the latest version.

Basic Usage: Windows Authentication

The provided command demonstrates how to connect to an MS SQL Server using Windows Authentication (Integrated Security).

python3 mssqlclient.py 'ARCHETYPE/sql_svc@<target-ip>' -windows-auth

Command Breakdown:

  • python3 mssqlclient.py: Invokes the script.
  • 'ARCHETYPE/sql_svc@<target-ip>': This specifies the target and the user context.
    • ARCHETYPE/sql_svc: Represents the domain (ARCHETYPE) and the username (sql_svc) you are trying to authenticate as. This user should have access to the SQL Server.
    • @<target-ip>: The IP address or hostname of the target MS SQL Server.
  • -windows-auth: This flag indicates that the tool should attempt to authenticate using NTLM (Windows Authentication) based on the current user’s context (if run on a domain-joined machine) or by relaying credentials. In penetration testing, this is often used with tools like crackmapexec or responder to relay credentials.

Other Authentication Methods

Connecting with Username and Password

You can explicitly provide a username and password:

python3 mssqlclient.py 'ARCHETYPE/sql_user:Password123!@<target-ip>'
# Or if no domain:
python3 mssqlclient.py 'sql_user:Password123!@<target-ip>'

Connecting with a Hash

For pass-the-hash scenarios (NTLM hash):

python3 mssqlclient.py 'ARCHETYPE/sql_user@<target-ip>' -hashes 'LMHASH:NTHASH'

Executing Commands

Once connected, you can use commands like enable_xp_cmdshell (if available and permissions allow) to execute OS commands.

# Inside mssqlclient.py shell
enable_xp_cmdshell
xp_cmdshell whoami

Disclaimer: This tool is intended for authorized security testing and ethical hacking purposes only. Unauthorized access to computer systems is illegal and unethical.