Oracle Database is reached through the TNS listener (port 1521), which routes a client to a database instance named by a SID or service name. The attack path is staged: enumerate the listener and valid SIDs, test accounts (Oracle is notorious for default credentials), then, with a database account, reach operating-system command execution through Java, the scheduler, or external tables. odat automates most of it.
What to reach for#
- Access and enumeration: TNS and SID enumeration, default and weak accounts, schema and hash extraction.
- Command execution: OS commands through
DBMS_SCHEDULER, Java stored procedures, and external tables. - File access: reading and writing host files through
UTL_FILEand a directory object. - Out-of-band: SSRF, NetNTLM capture on Windows, and blind exfiltration through the outbound packages.