💻
Classic SQL injection paired with rare database trick to hijack Windows servers
💻 Technology

Classic SQL injection paired with rare database trick to hijack Windows servers

Security researchers at Huntress investigated an attack in which a classic SQL injection on a public-facing Oracle-backed application allowed hackers to upload a rare post-exploitation toolkit called khunt. The toolkit enabled OS command execution, credential theft, and Windows registry hive exfiltration — a technique widely discussed but rarely seen in the wild. Defenders are advised to implement input sanitisation and tighten database configurations.

Comments

No comments yet