Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.
Resources
1Install
npx skillscat add youlianvr/oper-share/database-security Install via the SkillsCat registry.
Database Security Assessment
ACTION REQUIRED (execute immediately after reading)
NOW: Read precedent-pentest;Produce库禁止破坏性语句 unless 明确AllowNOW: scope write清实example、accountPermission、whetherAllowwrite/删NEXT: 客户sideToolPathACT: Exposure surface → Authentication → Authorization → Configuration → Exploit chainVerification(Security)
Scope
DatabasenotAuthorization/weakPassword/ErrorBinding 0.0.0.0
Permission过大、dangerousfunctioncan(xp_cmdshell、COPY PROGRAM、UDF)
Lateral:from应useaccountto DBA
NoSQL Injectionand Redis writefileetc.(Authorization环境)
Workflow
□ NetworkExposureand TLS
□ accountRoleand grantee
□ sensitive表访问Control
□ dangerousConfiguration:file_priv、xp_cmdshell、load_file
□ AuditLogwhether开启
□ BackupandSnapshotPermission
Toolchain
| Tool | purpose |
|------|------|
| 官方 CLI | ConnectionandEnumerate |
| sqlmap | InjectionVerification(Authorization) |
| nuclei | alreadyknowExposureTemplates |
| cloud RDS Control台Audit | Configuration |
References
references/db-misconfig-checklist.md../pentest-tools/../cloud-k8s/
Routing context
Upstream: MASTER R35
Downstream: 获 OS command → attack-chain;cloud托管 → cloud-k8s
Task completion checklist
whether避免notAuthorizationwrite删?
whether区分ConfigurationIssueandcanExploit chain?
Checklist?