Discussion

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Started by The Hacker News · 06 Aug 2026 12:39 · 1 Views · 0 Replies
Thread Starter #0
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.

Huntress, which tracks the toolkit as khunt,

Okumaya devam et...

You must be logged in to reply.

0 quotes selected