Oracle

Oracle Database has the most distinctive dialect of the major engines, and several of its quirks decide how injection payloads are written.

Every SELECT needs a FROM, so single-row queries select FROM DUAL. There is no LIMIT; row limiting is WHERE ROWNUM=1 or FETCH FIRST n ROWS ONLY (12c and later). Strings concatenate with ||, and CHR() builds them without quotes. Comments are -- and /* */. Crucially, Oracle does not support stacked queries through the usual JDBC and OCI drivers: a second ;-separated statement does not run, so multi-statement actions require an injectable PL/SQL block instead.

The catalog is the ALL_/USER_/DBA_ views (all_tables, all_tab_columns, all_users) and the V$ performance views (v$version, v$instance). Identity and context come from SELECT user FROM dual and SYS_CONTEXT('USERENV', ...).

Oracle's most powerful primitives live in supplied PL/SQL packages, and from 11g their network reach (UTL_HTTP, UTL_INADDR, UTL_TCP, UTL_SMTP, HTTPURITYPE) is gated by fine-grained Access Control Lists, so out-of-band and some error channels depend on an ACL grant as well as the package execute privilege. State these preconditions when a payload relies on them.

Techniques#

References#

  • Oracle Database SQL Language Reference and PL/SQL Packages and Types Reference
  • OWASP Testing Guide: Testing for SQL Injection

Cookie Consent

We use cookies to enhance your experience. Learn more