Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AI PRP: prestodb exposed UI and APIs #463

Open
lanced00m opened this issue Apr 11, 2024 · 0 comments
Open

AI PRP: prestodb exposed UI and APIs #463

lanced00m opened this issue Apr 11, 2024 · 0 comments

Comments

@lanced00m
Copy link
Contributor

lanced00m commented Apr 11, 2024

According to the prestodb introduction: Presto is a distributed SQL query engine designed to query large data sets distributed over one or more heterogeneous data sources.
from my tests on an exposed prestodb UI, attackers can execute arbitrary SQL queries in an exposed prestodb UI. I couldn't find a way to execute an os-level command, but performing a generic SQL query is easy.

we can run an instance quickly with docker: https://hub.docker.com/r/prestodb/presto
documentation: http://prestodb.io/docs/0.286/overview.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant