Penetration Testing mailing list archives
Re: Firebird pentesting
From: Steve Friedl <steve () unixwiz net>
Date: Tue, 29 Sep 2009 15:27:08 -0700
On Tue, Sep 29, 2009 at 10:26:40PM +0400, Taras wrote:
In one of last pentests I found network accessible Firebird DB with DBA default account. But I can't found any clients for Linux for FB/Interbase :( Couuld you advice something to connect and make query to FB from Linux? What pentesters point of view will be interesting in such access?
The installers for Linux are easy to find: http://firebirdsql.org/index.php?op=files&id=engine_205 The "isql" command lets you connect, though note that the ODBC package often includes an "isql" too. This installs in /opt/firebird. Steve -- Stephen J Friedl | Security Consultant | UNIX Wizard | 714 694-0494 steve () unixwiz net | Orange County, CA | Microsoft MVP | unixwiz.net ------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------
Current thread:
- Re: Firebird pentesting Christian Eric Edjenguele (Oct 02)
- <Possible follow-ups>
- Re: Firebird pentesting Paolo Scarabelli (Oct 02)
- Re: Firebird pentesting Ulises Retamal (Oct 02)
- Re: Firebird pentesting Steve Friedl (Oct 02)
- Re: Firebird pentesting Christian Eric Edjenguele (Oct 02)
- Re: Firebird pentesting Hénarès Sébastien (Oct 02)