Alexander Rubin
Principal Security Engineer, RDS Red Team Lead, Amazon Web Services
Are your database secure? No, not the application, the database! Usually, everyone is focused on the application security and consider the database server to be "protected" by the network firewalls. But what if the first layer of defense fails and your database is exposed from the internet or via SQL injection? Will a bad actor be able to escape from the database and get root shell or exfiltrate other database tenants data? Penetration tester's goal is to pretend to be a "bad actor" and try to find all the week spots in a simulated scenarios. I will show a number of "week spots" when dealing with opensource relational databases (MySQL and PostgreSQL) and how to protect from them.
Auf dieser Seite können Sie das Online-Video LinuxFest Northwest 2024: Pen-testing opensource databases (MySQL and PostgreSQL) mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer linuxfestnorthwest 30 April 2024 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 81 Mal angesehen und es wurde von 1 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!