Enable xp_cmdshell in SQL Server 2005

SQL  Server 2005 or later, for security purpose, following procedures are disabled by default:

  • xp_cmdshell : allows executing shell commands
  • sp_oacreate : creates an instance of an OLE object.
  • sp_makewebtask: creates output file

With sysadmin’s right, you can resurrect them:

Enable xp_cmdshell:

Exec sp_configure 'show advanced options',1;
RECONFIGURE;
EXEC sp_configure 'xp_cmdshell',1;
RECONFIGURE;

Enable sp_oacreate:

Exec sp_configure 'show advanced options',1;
RECONFIGURE;
exec sp_configure 'Ole Automation Procedures',1;
RECONFIGURE;

Enable sp_makewebtask:

Exec sp_configure 'show advanced options',1;
RECONFIGURE;
exec sp_configure 'Web Assistant Procedures',1;
RECONFIGURE;
Advertisements

Leave a comment

Filed under Hacking

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s