SShortSingh.
Back to feed

SQL Injection Attack Planted Credential-Stealing Toolkit Inside Oracle Database

0
·10 views

On July 27, 2026, cybersecurity firm Huntress detected a credential theft incident targeting an Oracle Database server via a SQL injection flaw in a public Apache Tomcat application's autocomplete feature. The attacker exploited poor input validation to execute a CREATE JAVA SOURCE command through an over-privileged JDBC connection, embedding a custom toolkit called 'khunt' directly as a compiled Oracle schema object. Once resident inside the database, khunt's components ran OS commands through oracle.exe with SYSTEM-level privileges, enabling filesystem enumeration, registry hive dumping, and credential harvesting from Oracle's internal user table. Tools including cmd.exe, PowerShell, reg.exe, and esentutl.exe were spawned from oracle.exe to copy SAM and SECURITY hives, which were staged on the Oracle data drive. Because the malicious toolkit existed as a database object rather than a conventional executable, many endpoint detection and antivirus tools failed to flag its initial deployment.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Python Multithreading Is Not Fake — But It Depends on the Task

A developer noticed significant speed gains after parallelizing a network data-fetching tool with Python threads, despite a colleague's claim that Python multithreading is 'fake' due to the Global Interpreter Lock (GIL). The GIL restricts Python so that only one thread executes bytecode at a time, which led to the misconception. However, the GIL is released during I/O waits, allowing other threads to run while one waits for a network response, which explains the real speedup observed. For CPU-bound tasks like image processing or heavy math, the GIL never releases meaningfully, making multithreading genuinely ineffective. The key distinction is that Python threads deliver real concurrency for I/O-bound work but not for CPU-bound operations.

0
ProgrammingHacker News ·

Opinion: Why Interstellar Travel May Remain Beyond Human Reach

A recently published opinion piece argues that humans will never succeed in traveling beyond the solar system. The article, hosted on erscream.com, outlines reasons why interstellar travel is likely to remain impossible for humanity. The piece has gained some traction on Hacker News, attracting a small number of upvotes. The post currently has no comments, suggesting it is in early circulation. The core argument centers on the immense physical and practical barriers that stand in the way of human interstellar exploration.

0
ProgrammingDEV Community ·

Developer Guide: How to Embed Virtual Cards via Partner API in 2026

A technical guide aimed at backend engineers outlines the key considerations for integrating virtual card issuance through partner APIs rather than building in-house. It covers critical architecture decisions including authentication flows, idempotency handling, and webhook design to prevent errors like duplicate card issuance. The guide highlights that white-label card API providers allow companies to plug into card programs without needing an EMI license or a full compliance department. A dedicated section addresses crypto-funded cards, noting that converting assets like BTC or USDT into spendable balances introduces unique failure modes absent in fiat-only systems. The guide also distinguishes card issuing APIs from broader Banking-as-a-Service platforms, emphasizing the importance of correctly scoping the integration from the outset.

0
ProgrammingDEV Community ·

Developer Builds Lightweight API Integration Proxy Using Django to Simplify Auth and Logging

A developer has created a lightweight API integration proxy called Asstgr, built on Django and PostgreSQL, to streamline how applications interact with multiple third-party APIs. The tool consolidates authentication, execution, and logging into a single layer, so applications can focus purely on business logic rather than managing per-API credentials and formats. The synchronous MVP uses the Requests library to dynamically construct downstream API calls via a unified execution endpoint. The developer chose Django for rapid prototyping and plans to migrate to asynchronous frameworks such as FastAPI or Go once the core logic is stable. Upcoming features include payload encryption, async execution via HTTPX, and caching with Redis.