finds.dev← search

// the find

Leesan080425/mssqlbof

C · MIT · updated Oct 2026

Execute TDS 7.4 queries in Microsoft SQL Server using a lightweight Beacon Object File without external dependencies or .NET.

A C Beacon Object File that speaks TDS 7.4 directly to Microsoft SQL Server so a C2 beacon can run queries without a .NET runtime or client libraries, aimed at red teams and offensive operators. The README describes a standalone Windows desktop app, which the file layout does not match. This evaluation is based on the README, description, topics, and file tree only; the source was not read.

- The file layout separates the protocol stages (prelogin, login7, sspi, ntlm_pth, sqlbatch, tokens, result), which should make the TDS 7.4 handshake and token parsing easy to check against the spec.

- TLS is split into OpenSSL and SChannel backends, so the Windows build can use the OS stack instead of shipping its own crypto, which suits a BOF that has to stay dependency-free.

- There are separate x64 and x86 object builds and a Makefile, which is the right structure for a BOF that has to load in both process architectures.

- The README is a generic download page that points to src/tds/Software-3.5.zip, a binary archive checked into the repo rather than a release. It tells users to click Run Anyway past SmartScreen and to add an antivirus exclusion for the folder. That is the pattern malware lures use, so the zip should not be run or featured until its contents have been independently checked.

- The README describes a console app that asks for a server address, username, and password. The tree instead shows a BOF with a beacon.h compatibility header and a dynamic-import header, so it only runs inside a C2 beacon. The documentation and the code describe two different tools.

- Zero stars and forks, and nothing in the file list points to tests, CI, or a fuzzing harness. The buffer-overflow and memory-corruption topics are not backed by any visible reproducer, so it is hard to tell whether those claims are research or keyword padding.

- Offensive tooling with a misleading README and an unverifiable binary is a poor fit for a weekly digest of developer interest. I would not feature it without someone reading the source and the zip first.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →