16 ms·
I was hoping for some sort of image or binary processing exploit too, but the attack just uses a Postgres vulnerability to execute arbitrary shell code. [0][1]
by fps 9y ago
I was hoping for some sort of image or binary processing exploit too, but the attack just uses a Postgres vulnerability to execute arbitrary shell code. [0][1] The fact that the executed code was buried in an image seems to just be a camouflage step for the attacker.
0. https://github.com/nixawk/pentest-wiki/blob/master/2.Vulnerability-Assessment/Database-Assessment/postgresql/postgresql_hacking.md https://github.com/nixawk/pentest-wiki/blob/master/2.Vulnera...
1. https://www.rapid7.com/db/modules/exploit/linux/postgres/postgres_payload https://www.rapid7.com/db/modules/exploit/linux/postgres/pos...
- anarazel 9y agoThere's no exploit here, superusers can do things, that's it.