Seminarinhalt
In this workshop you will analyze, learn and practice critical tasks for implementing highly secure SQL Server infrastructure. We’ll start with identifying security needs regarding database servers and look at the most common attack types and use them on ‘out of the box’ installation. In simple words we will hack our systems!
We will discuss impact of system and network security on databases server. Next, we will go through every layer of protection offered by SQL Server with lots of real-life examples and hands on labs. At the end we will look at the monitoring and auditing our infrastructure to detect threats and react to them. Additionally, we’ll play with security of other SQL Services and Azure SQL Databases. Our goal is to show and teach you how to protect your precious data in SQL Server environment and how database security mechanisms work. After the course you will be able to test and secure your SQL Server infrastructure.
All exercises are based on SQL Server 2019 and Windows Server 2019.
After the course you will be able to test and secure your SQL Server infrastructure and have knowledge for these topics:
We will discuss impact of system and network security on databases server. Next, we will go through every layer of protection offered by SQL Server with lots of real-life examples and hands on labs. At the end we will look at the monitoring and auditing our infrastructure to detect threats and react to them. Additionally, we’ll play with security of other SQL Services and Azure SQL Databases. Our goal is to show and teach you how to protect your precious data in SQL Server environment and how database security mechanisms work. After the course you will be able to test and secure your SQL Server infrastructure.
All exercises are based on SQL Server 2019 and Windows Server 2019.
After the course you will be able to test and secure your SQL Server infrastructure and have knowledge for these topics:
- Hacking SQL Server Infrastructure
- SQL Server security baseline concepts
- SQL Server Instance Security
- Managing Logins and Passwords
- Encryption in SQL Server
- Protecting database backups
- Monitoring and auditing
- Securing other SQL Server services
Programm
Hacking SQL Server Infrastructure
- Discovering SQL Server instances
- SQL injection using men in the middle
- Capturing SQL credentials using men in the middle
- Decrypting SQL Logins passwords
- Gaining access to SQL Server on compromised Windows Server
- Defining security objectives
- Configuring service accounts
- Auditing database permissions
- Implementing physical protection
- Configuring firewall
- Securing client-server communication
- Limiting permissions
- Securing CLR
- Implementing protection for extended procedures
- Protecting linked servers (OPENROWSET)
- Securing by using policies
- Hiding instance metadata
- Authentication options
- Implementing password policies
- Securing connection strings
- Customizing login / user authorization
- Key management
- Code and data encryption
- Managing certificates
- Transparent database encryption
- Encryption in HA and Disaster Recovery
- Securing backup files
- Setting backup file passwords and encryption
- Handling keys and certificate backups
- Security considerations while restoring to another SQL Server instance
- Login auditing options
- Data access auditing
- Data Manipulation Language custom auditing
- Policy-based management
- Forensics case study
- SQL Server Agent
- SQL Server Analysis Services
- SQL Server Reporting Services
- Azure SQL Database
Zielgruppen
This is an advanced course on Hacking and Securing SQL Server for Cybersecurity Specialists.
The course is perfect for:
The course is perfect for:
- Enterprise administrators
- Infrastructure architects
- Security professionals
- Systems engineers
- Network administrators
- IT professionals
- Security consultants
Vorkenntnisse
We recommend good hands-on experience in administering Microsoft SQL Server infrastructure with least 2 years in the field.
Wichtige Information
This Lighthouse training is held in English!
Immer noch ein TopTrainer!
Masterclass: Hacking and Securing SQL Server (HSS)
09.05.2019Immer noch ein TopTrainer!
— Marcus Michael B.Masterclass: Hacking and Securing SQL Server (HSS)
23.11.2018Sehr interessanter Kurs, Trainer war sehr gut
Masterclass: Hacking and Securing SQL Server (HSS)
16.04.2018Sehr interessanter Kurs, Trainer war sehr gut
— Manfred S.Sehr guter und informativer Kurs. Der Trainer war sehr kompetent.
Masterclass: Hacking and Securing SQL Server (HSS)
13.04.2018Sehr guter und informativer Kurs. Der Trainer war sehr kompetent.
— Markus S.