Web Jdbc Attacks

Turn an attacker-controllable database connection string / JDBC URL into RCE via the driver itself. Load when an app lets you set a DB host/URL/driver: a "test connection" form, a data-source config, an ETL/reporting/integration tool, or a processor that takes a JDBC URL. Signals: a jdbc: URL field, H2/MySQL/Postgres connection settings, Apache NiFi/Mirth/Metabase/DBeaver-style data-source config, "connection string", driver properties you can edit.

NoorQureshi 15f7352 3.5 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-jdbc-attacks commit 15f7352171

Frequently asked questions

npx skillmds@latest add noorqureshi/web-jdbc-attacks