CYBERSECURITYTRACKER
TRACKING7,218 stories in this site build1,512 vulnerability news stories in this site build
Permanent story citation

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3963

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers exploited a SQL injection vulnerability in a public-facing web application to gain Oracle database access, then compiled malicious Java code within the database itself to execute arbitrary commands. This technique avoided writing executable files to disk by leveraging Oracle's native compilation capabilities to deploy the khunt post-exploitation toolkit.

Why it matters: Organizations running Oracle databases exposed to SQL injection are at risk of post-compromise persistence and lateral movement without traditional file-based detection; patch SQL injection vulnerabilities and monitor database compilation activities immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers exploited a SQL injection vulnerability in a public-facing web application to gain Oracle database access, then compiled malicious Java code within the database itself to execute arbitrary commands. This technique avoided writing executable files to disk by leveraging Oracle's native compilation capabilities to deploy the khunt post-exploitation toolkit.

Why it matters: Organizations running Oracle databases exposed to SQL injection are at risk of post-compromise persistence and lateral movement without traditional file-based detection; patch SQL injection vulnerabilities and monitor database compilation activities immediately.

VendorsMicrosoftOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary