Global Manager - Howto

You might also like

Download as txt, pdf, or txt
Download as txt, pdf, or txt
You are on page 1of 1

Please, take care of your Global Manager server module.

You should also


block it, and set strict ip restrictions for it. Don't allow any non-trustable
gm ip addresses to connect it. It's vulnerable to SQL injections (and also, several
buffer
overflows).

PoC : get SMC, set ip address at ServiceManager.cfg to target server ip address,


and global manager
port, type "' shutdown -- " (without double quotes) into username field (or any
other), and try connecting.
MSSQL server will stop responding after this query.

Chernobyl
Skype: live:cherno0x2f

You might also like