World Congress 2026 Europe • Jul 10, 2026 • Session details

Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.

Fabiano Amorim

Can a standard user hijack your managed cloud database? See how abusing DDL triggers and un-sanitized T-SQL yielded full sysadmin rights across Azure, AWS, GCP, and Alibaba.

Pause
Mute Enter Fullscreen
#1 about 5 min

Identifying SQL injection vulnerabilities in internal stored procedures

Automating security checks reveals common flaws in complex internal queries where user input is unsafely concatenated.

#2 about 4 min

Validating SQL injection risks with a PowerShell module

A programmatic demonstration parses statements to pinpoint unsafe dynamic command concatenations and risks stemming from implicit data type conversions.

#3 about 5 min

Exploiting internal stored procedures to execute shell commands

System procedures inherently possess elevated privileges that attackers compromise to bypass execution restrictions and run operating system commands.

#4 about 3 min

Bypassing sysadmin restrictions across major cloud providers

Despite restrictive managed service guarantees, underlying architectural implementation flaws enable full privilege escalation across multiple cloud database environments.

#5 about 7 min

Exploiting managed instances on Azure and Alibaba Cloud

Bypassing weak internal mitigations and exploiting shared architectural environments exposes cross-tenant databases and plaintext system credentials.

#6 about 7 min

Hijacking administrative execution context using DDL event triggers

Malicious data definition triggers intercept automated administrative procedures to secretly elevate standard application users into elevated administrators.

#7 about 2 min

Hardening database environments through the principle of least privilege

Revoking default access to unneeded system capabilities proactively protects instances against chained privilege escalation attacks.

Matching moments

2:40 min

Examining real-world zero-day exploits in enterprise applications

Sonya Moisset · World Congress 2023

2:43 min

Understanding common web application vulnerabilities and risks

Jakub Andrzejewski · World Congress 2023

4:12 min

Exploiting cloud metadata servers and manipulating authentication tokens

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

2:55 min

Identifying common and emerging application injection attack vectors

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

2:40 min

Identifying command injection flaws in developer infrastructures

Vandana Verma Sehgal · LIVE

2:46 min

The risk of weak credentials in maintainer accounts

Vandana Verma Sehgal · LIVE