Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside the database and gain SYSTEM-level access to the underlying Windows server.
Attackers compile khunt inside Oracle after a web SQL injection, reach Windows SYSTEM, and stage credential data and registry hives locally.
A post-exploitation toolkit has been found compiled and stored inside an Oracle database as schema objects, giving attackers ...