- Web Penetration Testing with Kali Linux(Third Edition)
- Gilberto Najera Gutierrez Juned Ahmed Ansari
- 115字
- 2021-06-24 18:45:01
Database exploitation
No web penetration test is complete without testing the security of the backend database. SQL servers are always on the target list of attackers, and they need special attention during a penetration test to close loopholes that could be leaking information from the database. SQLNinja is a tool written in Perl, and it can be used to attack Microsoft SQL server vulnerabilities and gain shell access. Similarly, the sqlmap tool is used to exploit a SQL server that is vulnerable to a SQL injection attack and fingerprint, retrieve user and database information, enumerate users, and do much more. SQL injection attacks will be discussed further in Chapter 5, Detecting and Exploiting Injection-Based Flaws.
推薦閱讀
- 全屋互聯(lián):智能家居系統(tǒng)開發(fā)指南
- 30天自制操作系統(tǒng)
- Modern Web Testing with TestCafe
- 阿里云數(shù)字新基建系列:云原生操作系統(tǒng)Kubernetes
- Google系統(tǒng)架構(gòu)解密:構(gòu)建安全可靠的系統(tǒng)
- Persistence in PHP with the Doctrine ORM
- 嵌入式Linux驅(qū)動(dòng)程序和系統(tǒng)開發(fā)實(shí)例精講
- SharePoint 2013 應(yīng)用開發(fā)實(shí)戰(zhàn)
- 計(jì)算機(jī)系統(tǒng)開發(fā)與優(yōu)化實(shí)戰(zhàn)
- 直播系統(tǒng)開發(fā):基于Nginx與Nginx-rtmp-module
- Linux內(nèi)核觀測(cè)技術(shù)BPF
- OpenSolaris設(shè)備驅(qū)動(dòng)原理與開發(fā)
- Red Hat Enterprise Linux 6.4網(wǎng)絡(luò)操作系統(tǒng)詳解
- 精解Windows 10
- OpenVZ Essentials