Scott Sutherland's presentation covers hacking SQL Server using PowerShell, outlining discovery techniques, privilege escalation scenarios, and post-exploitation strategies. The primary tool discussed, powerupsql, facilitates SQL Server discovery, auditing, and exploitation with over 70 functions available. The presentation emphasizes the implications of weak passwords and the ability to escalate privileges from SQL Server logins to sysadmin or Windows accounts.
Related topics: