Comments on: SQL Vulnerability Assessment https://thomaslarock.com/2017/10/sql-vulnerability-assessment/ Thomas LaRock is an author, speaker, data expert, and SQLRockstar. He helps people connect, learn, and share. Along the way he solves data problems, too. Thu, 11 Jan 2018 19:16:00 +0000 hourly 1 https://wordpress.org/?v=6.7.2 By: Using sqlmap to Test For SQL Injection Vulnerabilities - Thomas LaRock https://thomaslarock.com/2017/10/sql-vulnerability-assessment/#comment-16235 Thu, 11 Jan 2018 19:16:00 +0000 https://thomaslarock.com/?p=18056#comment-16235 […] Server Audit to track changes made to jobs inside of SQL Agent. And another on the SQL Vulnerability Assessment feature in Azure. Today I’m going to write a bit about a third tool, sqlmap, an open-source […]

]]>
By: SQL Vulnerability Assessment Available in SSMS - Thomas LaRock https://thomaslarock.com/2017/10/sql-vulnerability-assessment/#comment-16197 Thu, 07 Dec 2017 21:27:49 +0000 https://thomaslarock.com/?p=18056#comment-16197 […] Vulnerability Assessment (VA) feature in now available in SSMS (SQL Server Management Studio)! I blogged about this feature in Azure recently, and hinted that SQL Vulnerability Assessment Available in SSMS would be coming soon. Well, today […]

]]>
By: ThomasLaRock https://thomaslarock.com/2017/10/sql-vulnerability-assessment/#comment-16169 Tue, 17 Oct 2017 15:29:00 +0000 https://thomaslarock.com/?p=18056#comment-16169 In reply to Hugo Shebbeare.

Yes! I am hopeful that we will see continued improvements with this feature, and soon!

]]>
By: Hugo Shebbeare https://thomaslarock.com/2017/10/sql-vulnerability-assessment/#comment-16167 Mon, 16 Oct 2017 01:27:00 +0000 https://thomaslarock.com/?p=18056#comment-16167 Nice post Thomas! Glad they finally released a product to rival IBM Security’s VA tool – hope that in the next versions they continue to not only build a great security tool for within the MSFT feature space, but also incorporate NIST/STIG, CIS, standards (known well in the CISSP space) that are matched for the passes settings, as well as include what CVEs are satisfied, correlated to the patching level.

]]>