官术网_书友最值得收藏!

Database exploitation

No web penetration test is complete without testing the security of the backend database. SQL servers are always on the target list of attackers, and they need special attention during a penetration test to close loopholes that could be leaking information from the database. SQLNinja is a tool written in Perl, and it can be used to attack Microsoft SQL server vulnerabilities and gain shell access. Similarly, the sqlmap tool is used to exploit a SQL server that is vulnerable to a SQL injection attack and fingerprint, retrieve user and database information, enumerate users, and do much more. SQL injection attacks will be discussed further in Chapter 5, Detecting and Exploiting Injection-Based Flaws.

主站蜘蛛池模板: 平乐县| 望谟县| 电白县| 林周县| 双城市| 合作市| 武安市| 墨脱县| 五指山市| 陆河县| 新巴尔虎右旗| 亳州市| 从江县| 河西区| 长沙县| 辽源市| 师宗县| 纳雍县| 个旧市| 麟游县| 泾川县| 延庆县| 浠水县| 淮滨县| 应用必备| 宣威市| 宜都市| 皋兰县| 饶阳县| 宁安市| 揭西县| 纳雍县| 山东省| 麦盖提县| 安乡县| 正阳县| 南岸区| 唐海县| 酒泉市| 石台县| 宣恩县|