Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
The Hacker News
5 days ago

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

By info@thehackernews.com (The Hacker News)

Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt,

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.