当数据库"反噬"——在 SQL Server 中定位数据
netspi.com | 博客 | #penetration-testing | #metasploit | #sensitive-data | #database-security | #sql-server | #tsql
摘要
Scott Sutherland 分享了在 SQL Server 中快速定位敏感数据的脚本:TSQL 脚本 FindDataByKeyword.sql 无需 SYSADMIN 权限,按关键字搜索各数据库中匹配的列并抽样数据;另提供 Metasploit 辅助模块 mssql_findandsampledata.rb 作为封装,适合 PCI 渗透测试取证。
- 发布时间
- 收录时间
Skip to content