You could've applied all 1,449 Oracle patches and still been hit by this attack

https://image.theregister.com/234063.jpg?imageId=234063&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert

In late July, Oracle released a mammoth security patch dump with 1,449 patches, in a perhaps unprecedented bad day for database admins.

None of them, it turns out, would have prevented the credential theft on an Oracle database server described by security platform Huntress.

“Even if it had been fully patched, everything working, it still would have happened,” said Craig Savage, cybersecurity lead at Oracle third-party support vendor Spinnaker Support, referring to the attack.

In July, Huntress was alerted to credential theft activity, according to a post from the security company. The attack involved a "simple" SQL injection exploiting an unnamed organization's public-facing web app.

Although SQL injections have a long history and are easy to avoid with good info-sec housekeeping, what happened next was more unusual.

“After gaining initial access, the threat...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more