Тёмный

LinuxFest Northwest 2024: Pen-testing opensource databases (MySQL and PostgreSQL) 

linuxfestnorthwest
Подписаться 9 тыс.
Просмотров 42
50% 1

Alexander Rubin
Principal Security Engineer, RDS Red Team Lead, Amazon Web Services
Are your database secure? No, not the application, the database! Usually, everyone is focused on the application security and consider the database server to be "protected" by the network firewalls. But what if the first layer of defense fails and your database is exposed from the internet or via SQL injection? Will a bad actor be able to escape from the database and get root shell or exfiltrate other database tenants data? Penetration tester's goal is to pretend to be a "bad actor" and try to find all the week spots in a simulated scenarios. I will show a number of "week spots" when dealing with opensource relational databases (MySQL and PostgreSQL) and how to protect from them.

Наука

Опубликовано:

 

29 апр 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии    
Далее
Joscha at Microsoft
48:46
Просмотров 1,5 тыс.
what is an SQL Injection?
0:55
Просмотров 450 тыс.
Мама ударила дочь #shorts #iribaby
00:17
Learn SQL Basics in Just 15 Minutes!
16:57
Просмотров 99 тыс.
Getting Started as a Robotics Software Engineer!
9:35
Stored Procedures in MySQL | Advanced MySQL Series
12:37
Power up all cell phones.
0:17
Просмотров 49 млн
Плохие и хорошие видеокарты
1:00