官术网_书友最值得收藏!

Database exploitation

No web penetration test is complete without testing the security of the backend database. SQL servers are always on the target list of attackers, and they need special attention during a penetration test to close loopholes that could be leaking information from the database. SQLNinja is a tool written in Perl, and it can be used to attack Microsoft SQL server vulnerabilities and gain shell access. Similarly, the sqlmap tool is used to exploit a SQL server that is vulnerable to a SQL injection attack and fingerprint, retrieve user and database information, enumerate users, and do much more. SQL injection attacks will be discussed further in Chapter 5, Detecting and Exploiting Injection-Based Flaws.

主站蜘蛛池模板: 额济纳旗| 仪陇县| 洪湖市| 呼和浩特市| 淄博市| 巫山县| 长岛县| 巨野县| 娄烦县| 岳普湖县| 涞水县| 福建省| 桐柏县| 鄂托克前旗| 江山市| 苏尼特左旗| 诸城市| 玛沁县| 澄城县| 县级市| 白水县| 米林县| 沈丘县| 安徽省| 南投市| 托克逊县| 思南县| 吕梁市| 桂阳县| 丹东市| 扶风县| 常州市| 聂拉木县| 崇州市| 乌鲁木齐县| 封开县| 漾濞| 诸暨市| 小金县| 关岭| 维西|