database

This ‘classic’ decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick | Daily Reports Online

Share


  • Huntress saw Oracle SQLi used to deploy rare khunt toolkit
  • Khunt enabled OS commands, credential theft, and registry hive exfiltration
  • Defense includes input sanitation and more

Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely.


Security researchers Huntress, who were called in to investigate the incident, said the investigation first showed a classic, decades-old technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not.



Similar Posts