Skip to content
← LibraryTechnique entry
DB-MYSQL-UDFExecution

MySQL UDF Library Injection

Authenticated MySQL root → CREATE FUNCTION from attacker-controlled .so to spawn shell commands.

§ Where this technique fits

DB-MYSQL-UDF is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.