Using the MS SQL2k preauth attack, uploading pwdump to dump hashes, using John the Ripper to crack the hashes:
http://www.ethicalhacker.net/content/view/75/24/
using MSF 2.x Web interfact to exploit the DCOM exploit and exploring the meterpreter payload.
http://www.ethicalhacker.net/content/view/87/24/