This 'Classic' Decades-Old SQL Injection Flaw Could Let Hackers Take over Entire Windows Servers, Thanks to a Nifty Database Trick
2 Articles
2 Articles
This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick
Huntress saw Oracle SQLi used to deploy rare khunt toolkitKhunt enabled OS commands, credential theft, and registry hive exfiltrationDefense includes input sanitation and more Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely. Security researchers Huntress, who were called in to investigate the incident, said the investigation first showed a classic, decades-ol…
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt,
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium

