Defending Database Servers
David Litchfield, Chris Anley, John Heasman, and Bill Grindlay

#Database
#Defending
#Hacker
#Handbook
#MySQL
#Sybase_ASE
#PostgreSQL
#IBM
#DB2
#SQL
#Shellcoder
#attacker
🧠 پایگاههای داده؛ هسته عصبی اقتصاد
🧠 پایگاههای داده در واقع مرکز عصبی اقتصاد ما هستند. هر بخش از اطلاعات شخصی شما در آنها ذخیره میشود—سوابق پزشکی، حسابهای بانکی، سابقه شغلی، حقوق بازنشستگی، ثبت خودرو، حتی نمرههای فرزندان شما و اینکه چه مواد غذایی خرید میکنید. حمله به پایگاههای داده میتواند بهشدت فلجکننده و در عین حال بیوقفه باشد.
🔐 هدف این کتاب و اهمیت آن
🔐 این کتاب بهعنوان یک ادامه ضروری برای The Shellcoder's Handbook، توسط چهار نفر از برترین متخصصان امنیت دنیا نوشته شده و به شما یاد میدهد چگونه به هفت مورد از محبوبترین سرورهای پایگاه داده نفوذ کنید و از آنها دفاع کنید. شما یاد میگیرید چگونه آسیبپذیریها را شناسایی کنید، حملات چگونه اجرا میشوند و چطور جلوی این تخریب را بگیرید. مهاجمان این دانش را دارند؛ شما هم باید داشته باشید.
🛡️ آنچه یاد میگیرید
🛡️ شناسایی و رفع حفرههای جدید در Oracle و Microsoft SQL Server
🛡️ یادگیری بهترین روشهای دفاع برای سرورهای IBM DB2، PostgreSQL، Sybase ASE و MySQL
🛡️ بررسی اینکه چگونه Buffer Overflow، افزایش سطح دسترسی از طریق SQL، سوءاستفاده از Stored Procedure یا Trigger و SQL Injection امکان نفوذ را فراهم میکنند
🛡️ شناخت آسیبپذیریهای خاص هر دیتابیس
🛡️ فهمیدن اینکه مهاجمان از قبل چه چیزهایی را میدانند
📚 فهرست مطالب
👨💻 درباره نویسنده
👨💻 David Litchfield در زمینه جستوجوی تهدیدهای جدید برای سیستمهای پایگاه داده و اپلیکیشنهای وب تخصص دارد و رکورد غیررسمی جهانی در کشف آسیبپذیریهای مهم را در اختیار دارد. او برای سازمانهای امنیتی دولتی بریتانیا و آمریکا سخنرانی کرده و از سخنرانان ثابت Black Hat Security Briefings است. او یکی از نویسندگان The Shellcoder’s Handbook، SQL Server Security و Special Ops است و در کنار آن مدیرعامل شرکت Next Generation Security Software Ltd نیز هست.
👨💻 Chris Anley یکی از نویسندگان The Shellcoder’s Handbook است که یک کتاب پرفروش در حوزه پژوهش آسیبپذیریهای امنیتی محسوب میشود. او مقالات و گزارشهای امنیتی متعددی درباره سیستمهایی مانند SQL Server، Sybase، MySQL، DB2 و Oracle منتشر کرده است.
👨💻 John Heasman مشاور ارشد امنیت در شرکت NGS Software است. او پژوهشگر بسیار فعالی در حوزه امنیت است و گزارشهای متعددی درباره محصولات مهمی مانند Microsoft Windows، RealPlayer، Apple QuickTime و PostgreSQL منتشر کرده است.
👨💻 Bill Grindlay مهندس نرمافزار و مشاور ارشد امنیت در NGS Software است. او روی ابزارهای اسکن آسیبپذیری مانند Typhon III و خانواده NGSSQuirreL کار کرده و یکی از نویسندگان کتاب راهنمای مدیران پایگاه داده یعنی SQL Server Security است.
🏢 درباره Next Generation Security Software Ltd
🏢 شرکت Next Generation Security Software Ltd یک شرکت مستقر در بریتانیاست که مجموعهای از ابزارهای ارزیابی آسیبپذیری سرورهای پایگاه داده را تحت خانواده NGSSQuirreL توسعه میدهد. این شرکت در سال ۲۰۰۱ تأسیس شده و بخش مشاوره امنیتی آن یکی از بزرگترین تیمهای تخصصی امنیت در اروپا محسوب میشود. هر چهار نویسنده این کتاب در این شرکت فعالیت دارند.
Databases are the nerve center of our economy. Every piece of your personal information is stored there-medical records, bank accounts, employment history, pensions, car registrations, even your children's grades and what groceries you buy. Database attacks are potentially crippling-and relentless.
In this essential follow-up to The Shellcoder's Handbook, four of the world's top security experts teach you to break into and defend the seven most popular database servers. You'll learn how to identify vulnerabilities, how attacks are carried out, and how to stop the carnage. The bad guys already know all this. You need to know it too.
Table of Contents
Chapter 1: Why Care About Database Security?
Chapter 2: The Oracle Architecture
Chapter 3: Attacking Oracle
Chapter 4: Oracle: Moving Further into the Network
Chapter 5: Securing Oracle
Chapter 6: IBM DB2 Universal Database
Chapter 7: DB2: Discovery, Attack, and Defense
Chapter 8: Attacking DB2
Chapter 9: Securing DB2
Chapter 10: The Informix Architecture
Chapter 11: Informix: Discovery, Attack, and Defense
Chapter 12: Securing Informix
Chapter 13: Sybase Architecture
Chapter 14: Sybase: Discovery, Attack, and Defense
Chapter 15: Sybase: Moving Further into the Network
Chapter 16: Securing Sybase
Chapter 17: MySQL Architecture
Chapter 18: MySQL: Discovery, Attack, and Defense
Chapter 19: MySQL: Moving Further into the Network
Chapter 20: Securing MySQL
Chapter 21: Microsoft SQL Server Architecture
Chapter 22: SQL Server: Exploitation, Attack, and Defense
Chapter 23: Securing SQL Server
Chapter 24: The PostgreSQL Architecture
Chapter 25: PostgreSQL: Discovery and Attack
Chapter 26: Securing PostgreSQL
David Litchfield specializes in searching for new threats to database systems and web applications and holds the unofficial world record for finding major security flaws. He has lectured to both British and U.S. government security agencies on database security and is a regular speaker at the Blackhat Security Briefings. He is a co-author of The Shellcoder’s Handbook, SQL Server Security, and Special Ops. In his spare time he is the Managing Director of Next Generation Security Software Ltd.
Chris Anley is a co-author of The Shellcoder’s Handbook, a best-selling book about security vulnerability research. He has published whitepapers and security advisories on a number of database systems, including SQL Server, Sybase, MySQL, DB2, and Oracle.
John Heasman is a principal security consultant at NGS Software. He is a prolific security researcher and has published many security advisories relating to high-profile products such as Microsoft Windows, Real Player, Apple Quick-Time, and PostgreSQL.
Bill Grindlay is a senior security consultant and software engineer at NGS Software. He has worked on both the generalized vulnerability scanner Typhon III and the NGSSQuirreL family of database security scanners. He is a co-author of the database administrator’s guide, SQL Server Security.
Next Generation Security Software Ltd is a UK-based company that develops a suite of database server vulnerability assessment tools, the NGSSQuirreL family. Founded in 2001, NGS Software’s consulting arm is the largest dedicated security team in Europe. All four authors of this book work for NGS Software.









