How I Would Attack SQL Server

No ratings

Presented at TechnoSecurity&DigitalForensics 2019 by

This isn’t a talk about best practices or how to configure your system. It’s designed to get into the mindset of a motivated, equipped adversary who wants to get in to a system or application, specifically SQL Server, and uses the full extent of his or her creativity to do so. During this session, we''ll look at both traditional and non-traditional weak points, how an attacker discovers them, exploits them, and then covers up his or her tracks. We’ll also discuss what we can do to compensate for a weakness we can’t fix, which revolves mostly around detection and response and how an attacker will respond to such countermeasures