Hacking SQL Server Stored Procedures – Part 1: (un)Trustworthy Databases
netspi.com | blog | #privilege-escalation | #sql-injection | #powershell | #metasploit | #sql-server | #trustworthy-database
Summary
When databases are marked TRUSTWORTHY but ownership stays privileged, web app database users can escalate to sysadmin; the walkthrough includes PowerShell, Metasploit, and SQL injection automation.
- Published
- Collected
Skip to content