On the forum you’ll see somebody telling me to perform impersonation and do the execute() trick after that. It’s confusing if you don’t follow along with the pages(forum and module) I got stuck myself until I went to the forum.
Only one of the users is able to execute commands remotely with admin privileges. The section doesn’t really specify exactly how to do anything it just shows you one example and leaves it up to you to figure rest out.
If you can take some time and experiment with different commands and see what the results are, The forum can give you some ideas of what commands to execute.
Find Fiona → Connect to RDP with Fiona → there connect to SQL with Fiona → Impersonate John → after that find linked SQL-servers → execute command on linked server → get the flag!
Hi, I am not sure at which step I am exactly.
I “think” I impersonated john correctly, but when I try execute commands on the linked server I get this error:
[-] ERROR(WIN-HARD\SQLEXPRESS): Line 1: Linked servers cannot be used under impersonation without a mapping for the impersonated login.
1> EXECUTE('xp_cmdshell 'whoami'(''sysadmin'')') AT
2> go
Msg 102, Level 15, State 1, Server WIN-HARD\SQLEXPRESS, Line 1
Incorrect syntax near 'whoami'.
It was not, it was the Syntax. I was able to fix it using chatgpt because I suck at understanding code. The code I posted already had the correct server name in it.
Whats up fellows, been stuck on this one for a while. Need some help, I have gotten all the way to impersonating john and finding the linked server however, unable to do the xp_cmdshell command. Any help would be appreciated.
I’m pretty sure you don’t have permission for BULK and I had to use double quotes e.g. " around my path. The answer is a mixture of the two of your pictures. You’re on the right path
Hi, for the first screenshot I am not sure that notepad.exe will work in shell environment (as i think it will open notepad interactively), better to use for example ‘type’ it is basically cat in cmd. Regarding the second screenshot, maybe you don’t have enabled something important on the linked server?