filmov
tv
Confused deputy problem for databases: a method ofr privilege escalation in MariaDB
Показать описание
Operation systems had a confused deputy based privilege escalations for ages. But does it exist in a database? In the session I will demonstrate a number of cases where a simple select can be used to escalate a privilege inside the MariaDB database
Alexander Rubin, Amazon Web Services
Alexander is a Principal Security Engineerat Amazon Web Services (AWS), leading RDS Red Team.
Alexander was working as MySQL principal consultant/architect for over 15 years, started with MySQL AB in 2006 (company behind MySQL database), Sun Microsystems, Oracle and then Percona. His security pentest/red teaming interest started with playing CTFs and performing opensource security research. Alexander is leading RDS (relational database as a service) Red Team at Amazon Web Services
Alexander Rubin, Amazon Web Services
Alexander is a Principal Security Engineerat Amazon Web Services (AWS), leading RDS Red Team.
Alexander was working as MySQL principal consultant/architect for over 15 years, started with MySQL AB in 2006 (company behind MySQL database), Sun Microsystems, Oracle and then Percona. His security pentest/red teaming interest started with playing CTFs and performing opensource security research. Alexander is leading RDS (relational database as a service) Red Team at Amazon Web Services
Confused deputy problem for databases: a method ofr privilege escalation in MariaDB
Confused Deputy Problem Explained
BSidesRDU 2022 - Confused deputy problem for MySQL & PostgreSQL: a method for privilege escalati...
SAINTCON 2023 - Alexander Rubin - Confused Deputy Problem
4.3 Confused Deputy Problem
The Confused Deputy Problem
Using IAM Enumeration to Explore the Confused Deputy Problem
SAA C03 — Origin Access Control
AdeptDC - AWS_CloudWatch_Read_only_Credential_Creation
Hardening Java's Access Control by Abolishing Implicit Privilege Elevation
Cross-site Request Forgery (CSRF) and Confused Deputies
Cloudy With a Chance of Vulnerabilities: Finding & exploiting vulnerabilities in cloud - Sagi &a...
AWS Scenario Based Interview Questions that are commonly asked for AWS (Amazon Web Services) roles
Scaling Identity & Access in Multi-Account Enterprises: Complexities & Strategies for Effect...
Take a Deep Dive Into Common SaaS Data Breaches and How to Avoid Them - AppOmni
Topeaks #19 - IAM: Identity and Access Management
AWS Solutions Architect Associate Certification Practice Questions | Question No. 24 #aws #shorts
Pen-testing opensource databases (MySQL and PostgreSQL) - Alexander Rubin
AWS Solutions Architect Associate Certification Practice Questions | Question No. 43 #aws #shorts
CSE 545 S16: 'Application Insecurity pt. 1'
GopherCon 2018: Tess Rinearson - An Over Engineering Disaster with Macaroons
LinuxFest Northwest 2024: Pen-testing opensource databases (MySQL and PostgreSQL)
AWS re:Invent 2018: The Theory and Math Behind Data Privacy and Security Assurance (SEC301)
Alexander Rubin, Martin Rakhmanov - Pen-testing opensource databases (MySQL and PostgreSQL)
Комментарии