With a privileged account (DBA or the right CREATE/EXECUTE grants), Oracle runs operating-system commands as its service account through several subsystems. odat wraps all three; pick whichever the account's privileges and the database version allow.
DBMS_SCHEDULER external jobs#
The scheduler can run an external executable as a job. It needs both CREATE JOB and CREATE EXTERNAL JOB; the external-job privilege is what actually lets the OS command run:
# ODAT splits the value on whitespace and does not support shell metacharacters (>, |, quotes),
# so point it at a plain executable or a pre-positioned wrapper script, not an inline one-liner
odat dbmsscheduler -s <target> -d <SID> -U user -P pass --exec "/tmp/run.sh"
Java stored procedures#
Where Java is installed, a stored procedure wrapping Runtime.exec runs commands in the database's JVM:
odat java -s <target> -d <SID> -U user -P pass --exec "id"
External-table preprocessor#
An external table with a preprocessor directive runs a program when the table is read, a route that works without Java:
odat externaltable -s <target> -d <SID> -U user -P pass --exec "/path" "id"
# externaltable can also read host files with --getFile (case-sensitive); it has no write option
Exploitation notes#
- Commands run as the Oracle service account (
oracleon Linux, often a privileged service account on Windows), so the payoff is host access as that account. - The three sinks need different privileges: pick based on what enumeration showed (
CREATE JOBandCREATE EXTERNAL JOBfor the scheduler,CREATE PROCEDUREfor Java,CREATE ANY DIRECTORYfor external tables), and letodattry them in turn. - The external-table route also reads host files (
--getFile), useful when you only need to steal a file rather than run a command. - PL/SQL injection in a
DEFINER-rights package can supply the missing privilege, turning a low account into one that reaches these sinks.
Tools#
- ODAT (
dbmsscheduler,java,externaltable): automated command execution across all three sinks. - sqlplus: run the PL/SQL directly where you prefer manual control.