Database Penetration Testing

Database security testing is an extremely under-looked component of an organisation’s security and hence the most vulnerable. And of course, the Database is also the location in which vast and rich amounts of data may reside. 7safe’s penetration testing consultants analyse the security of the database from a number of perspectives including;
- Attacks coming from internal users (authenticated and un-authenticated access)
- Security of the data within the database (e.g. encryption/hashing techniques used for storing sensitive data)
- Database hardening and security
Over the years and through our application security testing programme, 7safe has developed extensive experience with the following database products:
- Microsoft SQL Server (all versions)
- Oracle Database (all versions and all platforms)
- MySQL Server (all versions and all platforms)
Oracle Database Security White Paper
7Safe’s Principal Security Consultant, Sumit “Sid” Siddharth, speaks CEO Alan Phillips about hacking Oracle via web applications here. Our recent white paper “Hacking Oracle from the Web: Exploiting SQL Injection from Web Applications can be located here.

