Get a Pentest and security assessment of your IT network.

News

Serving Up Malicious PDFs Through SQL Injection

Researchers from FishNet Security developed a new attack technique against websites that serve up binary file content like PDFs from dynamically built URLs. The technique they developed was precipitated by a real-world penetration test and code review conducted by Shawn Asmus and Kristov Widak. Their methods give attackers the means to stealthily extract data and serve up hidden malware by attacking SQL injection vulnerabilities on these types of sites. They also believe that it could be used against Web applications that deliver other content types beyond PDF.”]

Source: https://www.darkreading.com/database-security/serving-up-malicious-pdfs-through-sql-injection

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Thousands of Magento websites compromised to serve malware

News

Office 365 Secure Score: An Introduction