Oracle SQL | 1521

  • Scan SIDs

odat sidguesser -s 10.10.10.82
  • Brute force Passwords

odat passwordguesser -s 10.10.10.82 -d XE --accounts-file /usr/share/odat/accounts/accounts.txt
  • Login to SQPLUS Database

## ------------------| Setup
sudo apt-get install oracle-instantclient-sqlplus
which sqlplus
export ORACLE_HOME=/usr/lib/oracle/19.6/client64/
export LD_LIBRARY_PATH=$ORACLE_HOME/lib
export PATH=$ORACLE_HOME/bin:$PATH

## ------------------| Login as user
sqlplus <USERNAME>/'<PASSWORD>'@<IP>:1521/XE

## ------------------| Login as superuser
sqlplus scott/tiger@10.10.10.82:1521/XE as sysdba
  • SQLPLUSS Quarries

select * from session_privs;
select * from user_role_privs;
  • Read File

  • Write File

  • Write bind shell. (aspx)

Last updated