Urgent.News

What's breaking now, across thousands of outlets.

Science

You could've applied all 1,449 Oracle patches and still been hit by this attack

Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert

You could've applied all 1,449 Oracle patches and still been hit by this attack

In late July, Oracle released a massive security patch update containing 1,449 patches in what may have been an unprecedented day for database administrators. However, according to Craig Savage, cybersecurity lead at Spinnaker Support, none of these patches would have prevented a credential theft incident on an Oracle database server.

Huntress, a security platform, reported detecting credential theft activity in July, which involved a simple SQL injection exploiting a public-facing web application. After gaining access, the attackers dropped a post-exploitation toolkit, known as khunt, into the Oracle database using a Java source. This technique, while not entirely novel, had not been widely documented in the wild.

Oracle's database includes an embedded Java Virtual Machine (JVM), and users can store Java source code as a database object. The attackers achieved this by using Java source code from Tomcat through the database connection, which was then compiled as a stored schema object within the database. Savage emphasized that Oracle's own JDK allows for the execution of Java programs within the database, a feature that should be limited to the DBA user and disabled in production environments.

He warned that cybercriminals are increasingly exploiting legitimate functionality, rather than just seeking vulnerabilities. Despite Oracle releasing a significant number of patches, Savage stressed that organizations must not neglect basic security measures.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Science

More from Tuesday 25 August →