Get a Pentest and security assessment of your IT network.

News

Serving Up Malicious PDFs Through SQL Injection

Researchers from FishNet Security developed a new attack technique against websites that serve up binary file content like PDFs from dynamically built URLs. The technique they developed was precipitated by a real-world penetration test and code review conducted by Shawn Asmus and Kristov Widak. Their methods give attackers the means to stealthily extract data and serve up hidden malware by attacking SQL injection vulnerabilities on these types of sites. They also believe that it could be used against Web applications that deliver other content types beyond PDF.”]

Source: https://www.darkreading.com/database-security/serving-up-malicious-pdfs-through-sql-injection

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin