Comment by nhinck3
6 hours ago
They weren't publicly facing, but the website was just a very thin wrapper that exposed a SAS server (I believe) to queries from the internet.
And if you are at all familiar with SAS, you will understand how trivial command injection is.
No comments yet
Contribute on Hacker News ↗