Sploitus New Exploits Target Microsoft SQL Server and SQL Injection Vulnerabilities
Article Content
- •MSSQLand allows seamless exploitation of Microsoft SQL Server with minimal detection.
- •SQLMate automates the discovery of vulnerable sites and admin panels using SQL injection.
- •Both tools could be misused for malicious purposes, increasing the risk of exploitation.
Two new cybersecurity tools, MSSQLand and SQLMate, have been released targeting Microsoft SQL Server and SQL injection vulnerabilities respectively. MSSQLand is a post-exploitation tool designed for red team operators to navigate and exploit SQL Server environments with minimal detection. It allows for cascading impersonation and authentication using Windows tokens and pass-the-hash techniques. SQLMate, on the other hand, enhances SQLMap functionalities by automating the discovery of vulnerable sites and admin panels, and can crack various hash types quickly. Both tools are aimed at security professionals for penetration testing but could be misused by malicious actors. The release of these tools raises concerns about potential exploitation in the wild, especially given the capabilities they offer for bypassing security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cobalt Strike in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a signed kernel-mode driver that enhances the malware's stealth, allowing it to hide processes and…
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their tactics to target cloud environments, specifically Azure, by hijacking high-privilege…