Oracle Database

Oracle Database is reached through the TNS listener (port 1521), which routes a client to a database instance named by a SID or service name. The attack path is staged: enumerate the listener and valid SIDs, test accounts (Oracle is notorious for default credentials), then, with a database account, reach operating-system command execution through Java, the scheduler, or external tables. odat automates most of it.

What to reach for#

  • Access and enumeration: TNS and SID enumeration, default and weak accounts, schema and hash extraction.
  • Command execution: OS commands through DBMS_SCHEDULER, Java stored procedures, and external tables.
  • File access: reading and writing host files through UTL_FILE and a directory object.
  • Out-of-band: SSRF, NetNTLM capture on Windows, and blind exfiltration through the outbound packages.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more