This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick
Date:
Fri, 07 Aug 2026 14:15:00 +0000
Description:
Huntress spotted a white whale - a malicious toolkit stored as a database object.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Huntress saw Oracle SQLi used
to deploy rare khunt toolkit Khunt enabled OS commands, credential theft, and registry hive exfiltration Defense includes input sanitation and more Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely.
Security researchers Huntress, who were called in to investigate the
incident, said the investigation first showed a classic, decades-old
technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not. This granted the attackers the ability to upload a database-resident, posts-exploitation toolkit named
khunt. This technique is something of a cyber-white whale: its been widely discussed but rarely seen in the wild. Latest Videos From TechRadar Watch
full video here: How to defend What happened next, however, raised our eyebrows, Huntress said. After performing SQL injection, the threat actor managed to upload a database-resident, post-exploitation toolkit named khunt. This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec however, the use of
the technique in the wild has rarely been documented.
As a toolkit, khunt granted the attackers multiple capabilities, including loading cmd.exe on the system and running arbitrary OS commands, steal usernames and passwords, listing, reading, searching, and checking file sizes (essentially looking around the compromised system), unzipping files, and more. You may like HP warns hackers are turning popular remote access tools into dangerous, stealthy backdoors Oracle warns of critical PeopleSoft attack affecting hundreds of customers Ghost CMS flaw hijacked to target hundreds of websites with ClickFix attacks
Of all the things they could have done, the attackers opted to run a PowerShell command and invoke the Windows Registry tool, copying the SAM, SECURITY and SYSTEM registry hives. They can later use the copies to extract and decode password hashes for local accounts on the system, the researchers explained.
To defend against such attacks, Huntress recommends making sure the forms arent injectable. Practice proper input sanitization and query parameterization for any inputs, they warned. It's also important to ensure that users with the ability to execute queries aren't overprovisioned. Are
you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro
newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Even if someone manages to pull off SQL injection, user accounts should not
be capable of authoring Java sources or running stored procedures. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/this-classic-decades-old-sql-injection- flaw-could-let-hackers-take-over-entire-windows-servers-thanks-to-a-nifty-data base-trick
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)