Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.

Huntress, which tracks the toolkit as khunt,

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Why Did OpenAI’s Head of Ethics Chloé Bakalar Leave?

Why Did OpenAI’s Head of Ethics Chloé Bakalar Leave? Source: Hacker News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure

Suzanne: AI tool for designing and manufacturing physical products

Suzanne: AI tool for designing and manufacturing physical products Source: Hacker News