Guides authorized database security assessment across PostgreSQL, MySQL, MSSQL, Mongo and Redis, covering exposure, authz and misconfiguration.
- What it does
- Provides a structured workflow for authorized database security assessment: network exposure and TLS, account roles and grants, sensitive table access control, dangerous configuration such as file_priv, xp_cmdshell and load_file, audit logging, and backup permissions. It lists a toolchain including official CLIs, sqlmap, nuclei and cloud RDS console auditing, and points to a misconfiguration checklist reference. It also includes routing notes for escalation to OS command or cloud-hosted follow-up work.
- When to use it
- Use when assessing database security in an authorized engagement, such as checking for unauthenticated access, weak credentials, wrong binding, excessive privileges, dangerous features or NoSQL and Redis abuse paths. It suits scoping and checklist-driven review of database exposure and configuration.
- Requirements
- Instructions only; no scripts are shipped. It references a checklist file and expects database client tooling, sqlmap, nuclei and cloud RDS console access, plus explicit authorization and scope for the target instances.