World Congress 2026 Europe Jul 10, 2026 Session details

Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.

Fabiano Amorim

Can a standard user hijack your managed cloud database? See how abusing DDL triggers and un-sanitized T-SQL yielded full sysadmin rights across Azure, AWS, GCP, and Alibaba.

Pause
Mute Enter Fullscreen
#1 about 5 min

Identifying SQL injection vulnerabilities in internal stored procedures

Automating security checks reveals common flaws in complex internal queries where user input is unsafely concatenated.

#2 about 4 min

Validating SQL injection risks with a PowerShell module

A programmatic demonstration parses statements to pinpoint unsafe dynamic command concatenations and risks stemming from implicit data type conversions.

#3 about 5 min

Exploiting internal stored procedures to execute shell commands

System procedures inherently possess elevated privileges that attackers compromise to bypass execution restrictions and run operating system commands.

#4 about 3 min

Bypassing sysadmin restrictions across major cloud providers

Despite restrictive managed service guarantees, underlying architectural implementation flaws enable full privilege escalation across multiple cloud database environments.

#5 about 7 min

Exploiting managed instances on Azure and Alibaba Cloud

Bypassing weak internal mitigations and exploiting shared architectural environments exposes cross-tenant databases and plaintext system credentials.

#6 about 7 min

Hijacking administrative execution context using DDL event triggers

Malicious data definition triggers intercept automated administrative procedures to secretly elevate standard application users into elevated administrators.

#7 about 2 min

Hardening database environments through the principle of least privilege

Revoking default access to unneeded system capabilities proactively protects instances against chained privilege escalation attacks.

Matching moments

2:40 min

Examining real-world zero-day exploits in enterprise applications

Sonya Moisset · WWC 2023

2:43 min

Understanding common web application vulnerabilities and risks

Jakub Andrzejewski · WWC 2023

4:12 min

Exploiting cloud metadata servers and manipulating authentication tokens

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

2:55 min

Identifying common and emerging application injection attack vectors

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

2:40 min

Identifying command injection flaws in developer infrastructures

Vandana Verma Sehgal · LIVE

2:46 min

The risk of weak credentials in maintainer accounts

Vandana Verma Sehgal · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar