SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  PostgreSQL for Windows Insecure Library Loading

Category: DB-ATTACKS      

On default Microsoft Windows installations of PostgreSQL the postgres service account may write to the current directory. UDF DLL's may be sourced from there as well. Because the payload is run from DllMain, it does not need to conform to specific Postgres API versions.

References
http://en.wikipedia.org/wiki/Arbitrary_code_execution


Relevant Information