2 ms·
This might seem shocking, but I did internals for many years and the number of networks I completely compromised via SQL Server is pretty funny. Almost all of t
by bitexploder 7y ago
This might seem shocking, but I did internals for many years and the number of networks I completely compromised via SQL Server is pretty funny. Almost all of them. sa/(blank) -- run xp_cmdshell, abuse server privileges to pivot to other servers or right to domain admin, then compromise their non windows environment with all the access. Networks still get owned this way on internals / red teams all the time. Granted we expect a company with all our personal data to do better, but they are still just a big company making the same terrible choices as everyone else :)