SQL Server under attack: SQL Injection
Proposed session for SQLBits 2026TL; DR
In this demo-based session, Andreas Wolter, former Program Manager for SQL security at Microsoft will walk you through different types of SQLInjection attacks. You'll learn how specific configuration settings can pose risks to your environment.
Session Details
One of the most frequently attacked targets is the data stored on database servers and SQL Injection remains one of the most prevalent attack methods.
In this demo-based session, Andreas Wolter, former Program Manager for SQL security at Microsoft will demonstrate several real-life attacks - ranging from simple data reading to service disruption through various manual SQL Injection techniques. He’ll cover privilege escalation to sysadmin level and even a DoS attack on SQL Server using SQL commands.
If you have a database server that can be accessed by processes beyond your direct control or through frontend applications, and you’re concerned about the potential security implications, this session is for you. You'll learn how specific configuration settings can pose risks to your environment, helping you engage more effectively with your developers or database application vendors to mitigate security risks in your SQL Server environment.
In this demo-based session, Andreas Wolter, former Program Manager for SQL security at Microsoft will demonstrate several real-life attacks - ranging from simple data reading to service disruption through various manual SQL Injection techniques. He’ll cover privilege escalation to sysadmin level and even a DoS attack on SQL Server using SQL commands.
If you have a database server that can be accessed by processes beyond your direct control or through frontend applications, and you’re concerned about the potential security implications, this session is for you. You'll learn how specific configuration settings can pose risks to your environment, helping you engage more effectively with your developers or database application vendors to mitigate security risks in your SQL Server environment.
3 things you'll get out of this session
understand the different types of SQLinjection
learn how SQLinjection can be prevented
learn about specific high-risk settings in SQL server
Speakers
Andreas Wolter's other proposed sessions for 2026
Contained Availability Groups – Best Practices from Real-World Projects - 2026
De-mystifying SQL Security: Open Discussion and Real-World Insights - 2026
Enhancing Data Security for SQL Server and Azure SQL: A Strategic Approach - 2026
Practical Performance Monitoring & Troubleshooting for SQL Server and AzureSQL - 2026
Quickstart into database Performance Monitoring & Troubleshooting - 2026