Extract MSSQL Link Password
Last updated
Last updated
Step 1: Get Local Instances
Step 2 : Get the current User
Step 3: Get the version
Step 4: Check if you can impersonate sa
Step 5: Enable DAC
Step 6: Check if port 1434 is enabled
Step 7: If you dont see 1434 enabled see below
Step 8: Check if you have -T7806 in SQL Args. If you dont see below
Step 9 : Add SQLArg3 as -T7806
Step 10: Check if you have SQLBrowser running
Step 11: Check if you have named pipes enabled
Step 12: Restart the services
Step 13: Check if UDP port 1434 is now enabled
Extract the Link Password
Reference:
Create SA account