HTB Querier Writeup — MSSQL Exploitation (2026)
SMB guest access → Excel macro with MSSQL creds → Responder hash steal via xp_dirtree → xp_cmdshell → reverse shell.
SMB guest access → Excel macro with MSSQL creds → Responder hash steal via xp_dirtree → xp_cmdshell → reverse shell.
Quick reference for the Impacket tools I use most — mssqlclient, GetUserSPNs, GetNPUsers, secretsdump, psexec, and more.
The enumeration methodology I use on every box. Port scanning, service enumeration, and what to check first.
Proving Grounds box — anonymous FTP, SmarterMail on a weird port, .NET deserialization RCE straight to SYSTEM. No privesc needed.