13don MSN
This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers
Huntress spotted a white whale - a malicious toolkit stored as a database object.
Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside the database and gain SYSTEM-level access to the underlying Windows server.
Attackers compile khunt inside Oracle after a web SQL injection, reach Windows SYSTEM, and stage credential data and registry hives locally.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results