官术网_书友最值得收藏!

Database exploitation

No web penetration test is complete without testing the security of the backend database. SQL servers are always on the target list of attackers, and they need special attention during a penetration test to close loopholes that could be leaking information from the database. SQLNinja is a tool written in Perl, and it can be used to attack Microsoft SQL server vulnerabilities and gain shell access. Similarly, the sqlmap tool is used to exploit a SQL server that is vulnerable to a SQL injection attack and fingerprint, retrieve user and database information, enumerate users, and do much more. SQL injection attacks will be discussed further in Chapter 5, Detecting and Exploiting Injection-Based Flaws.

主站蜘蛛池模板: 汤原县| 怀来县| 北海市| 关岭| 措美县| 揭东县| 景德镇市| 邵东县| 赣榆县| 蒙阴县| 白城市| 亚东县| 安远县| 黎城县| 余庆县| 西林县| 静乐县| 剑川县| 北宁市| 恩平市| 黄陵县| 南漳县| 宜兰市| 墨脱县| 关岭| 前郭尔| 昂仁县| 呈贡县| 青海省| 东山县| 龙里县| 平武县| 和田县| 邯郸县| 奈曼旗| 洪洞县| 吉林省| 南汇区| 满洲里市| 南召县| 遂川县|