Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt,

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thehackernews.com →

More in Tech

More from Thursday 6 August →