logo

Yer a Wizard! Tagging Hard-coded Credentials Can Lead to Finding Magic (Numbers)

ID: d28c58b0-f1d2-5e87-9865-f53458894443

STIX ID: report--d28c58b0-f1d2-5e87-9865-f53458894443

Feed Name: GreyNoise Labs

Threat Score
45/100

Date Published: 2024-12-03

Date Updated: 2026-04-27

Author: Konstantin Lazarev

...
...

This research note describes CVE-2024-6633: FileCatalyst Workflow exposes its embedded HSQLDB via published default credentials. The author reproduces the service, demonstrates successful authentication using a Python JDBC connector, inspects the protocol traffic (identifying the HSQLDB NETWORK_COMPATIBILITY_VERSION_INT magic value), and provides Suricata detection signatures to detect the protocol and the default credentials on the network.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.