Yer a Wizard! Tagging Hard-coded Credentials Can Lead to Finding Magic (Numbers)
ID: d28c58b0-f1d2-5e87-9865-f53458894443
STIX ID: report--d28c58b0-f1d2-5e87-9865-f53458894443
Feed Name: GreyNoise Labs
Threat Score
This research note describes CVE-2024-6633: FileCatalyst Workflow exposes its embedded HSQLDB via published default credentials. The author reproduces the service, demonstrates successful authentication using a Python JDBC connector, inspects the protocol traffic (identifying the HSQLDB NETWORK_COMPATIBILITY_VERSION_INT magic value), and provides Suricata detection signatures to detect the protocol and the default credentials on the network.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
