Crypto Ticker:
sysadmin from Cyber Security News

Hackers Hid a Remote-Control Toolkit Inside Oracle to Take Over a Windows Server

Tushar Subhra Dutta
4 hours ago
6 Views
0 Comments
Hackers Hid a Remote-Control Toolkit Inside Oracle to Take Over a Windows Server

A routine web application weakness has been tied to a serious Windows Server compromise after attackers used SQL injection to plant a remote-control toolkit inside an Oracle database. The incident shows how a poorly protected form can become a path from a public website to the operating system behind it. The attackers targeted a public-facing Java and Tomcat application connected to Oracle. By submitting database commands through an autocomplete search feature that did not properly check input, they were able to make the database process commands and prepare the next stage of the intrusion. Researchers at Huntress identified the activity after detecting attempts to steal credentials from a server hosting Oracle. The...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!