4 ms·
> So unless the attacked application uses a superuser for database access (which is a big security hole to begin with) or uses a superuser account with a weak
by zombieprocesses 9y ago
> So unless the attacked application uses a superuser for database access (which is a big security hole to begin with) or uses a superuser account with a weak password and allow superuser access from the outside, I don't see how this could be exploited.
It can't be exploited if the security "best practices" are used. But I've come across situations where people were using "sa" as the account for production SQL Server connections because they just didn't know any better. Things are much better in the linux/bsd world where there is generally more competence and people tend to know what they are doing.
Having said that, things are getting better. IT/developers are much more mindful of security concerns today than 10 years ago.