Black & White Path
Aug 7, 2026 · Information Security
From SQL Injection to SYSTEM Privileges: How Attackers Hide Backdoors Inside Oracle Databases
A recent Huntress investigation reveals how attackers leveraged a web‑app SQL injection to compile the khunt tool as internal Java objects in an Oracle database, then used those objects to execute commands, steal credentials and obtain Windows SYSTEM privileges, highlighting the stealth of in‑database backdoors.
Database SecurityMITRE ATT&CKOracle
0 likes · 9 min read
