Huntress discovered active intrusions targeting FOUNDATION Accounting Software, widely used in the construction industry. Attackers are brute-forcing publicly exposed MSSQL instances (TCP port 4243) and gaining full access using unchanged default credentials for the 'sa' and 'dba' accounts. Once in, they enable xp_cmdshell to execute OS commands directly from SQL. Across 500+ monitored hosts, 33 were confirmed publicly exposed with default credentials. Mitigations include rotating credentials, removing public internet exposure, and disabling xp_cmdshell.

4m read timeFrom huntress.com
Post cover image
Table of contents
How It WorksHow To Stay ProtectedHow We Discovered the ThreatHow Huntress Has Responded