130 likes | 151 Views
Dive into SQL Server forensics, uncover hidden insights, and gain expertise in network sniffing, pass-the-hash techniques, and more. Discover undocumented data kept within SQL Server. Connect with the expert Argenis Fernandez for a rewarding journey. Explore now!
E N D
DISCLAIMER! • Don’t try this at home • If you break your system(s), it’s on you – not me, not the Security VC leaders/volunteers, not PASS • If you use this to hack someone, make sure to leave no trace • Kidding, the NSA knows.
About… • Data Platform (fka SQL Server) MVP • Principal Data Architect @ Pure Storage • Former Board of Directors @ PASS • Formerly Senior Consultant @ Microsoft • Microsoft Certified Master • VMware vExpert • DBA/Dev/SysAdmin for 19 years • Regular Speaker (PASS Summit, PASS SQLRally, SQLBits XI, TechEd, IT/DevConnections) • Founded the Security Virtual Chapter for PASS • Twitter enthusiast and occasional blogger
Agenda • SQL Server forensics • Local admin = sysadmin • Network sniffing • Pass-the-hash • Finding undocumented stuff
Where stuff is kept/persisted SQL Server Forensics
Assumptions are bad. Local admin = sysadmin
Smoke and mirrors. Network sniffing
20 year old attack vector Pass-the-hash
Moar! Finding undocumented stuff
Contact Info • argenis@purestorage.com • @DBArgenis on Twitter • http://www.sqlblog.com/blogs/argenis_fernandez/ • http://blog.purestorage.com/author/argenis/