Sploitus

Exploit for Oracle Database Attacking Tool: ODAT

n0where · 2018-02-23

Exploit Code

MARKDOWN91 lines
## https://sploitus.com/exploit?id=N0WHERE:172575
** ODAT ** (Oracle Database Attacking Tool) is an open source ** penetration testing ** tool that tests the security of ** Oracle Databases remotely ** . 

Usage examples of ODAT: 

  * You have an Oracle database listening remotely and want to find valid ** SIDs ** and ** credentials ** in order to connect to the database 
  * You have a valid Oracle account on a database and want to ** escalate your privileges ** to become DBA or SYSDBA 
  * You have a Oracle account and you want to ** execute system commands ** (e.g. ** reverse shell ** ) in order to move forward on the operating system hosting the database 

Tested on Oracle Database ** 10g ** , ** 11g ** and ** 12c ** (12.1.0.2.0). 

##  Features 

Thanks to ODAT, you can: 

  * search ** valid SID ** on a remote Oracle Database listener via: 
  * a dictionary attack 
  * a brute force attack 
  * ALIAS of the listener 
  * search Oracle ** accounts ** using: 
  * a dictionary attack 
  * each Oracle user like the password (need an account before to use this attack) 
  * ** execute system commands ** on the database server using: 
  * DBMS_SCHEDULER 
  * JAVA 
  * external tables 
  * oradbg 
  * ** download files ** stored on the database server using: 
  * UTL_FILE 
  * external tables 
  * CTXSYS 
  * DBMS_LOB 
  * ** upload files ** on the database server using: 
  * UTL_FILE 
  * DBMS_XSLPROCESSOR 
  * DBMS_ADVISOR 
  * ** delete files ** using: 
  * UTL_FILE 
  * ** gain privileged access ** using these following system privileges combinations (see help for _ privesc _ module commands): ( ** NEW ** : 2016/02/21) 
  * CREATE ANY PROCEDURE 
  * CREATE PROCEDURE and EXECUTE ANY PROCEDURE 
  * CREATE ANY TRIGER (and CREATE PROCEDURE) 
  * ANALYZE ANY (and CREATE PROCEDURE) 
  * CREATE ANY INDEX (and CREATE PROCEDURE) 
  * ** send/reveive HTTP requests ** from the database server using: 
  * UTL_HTTP 
  * HttpUriType 
  * ** scan ports ** of the local server or a remote server using: 
  * UTL_HTTP 
  * HttpUriType 
  * UTL_TCP 
  * ** capture a SMB authentication ** through: 
  * an index in order trigger a SMB connection 
  * exploit some CVE: 
  * the [ ** CVE-2012-3137 ** ](<http://cvedetails.com/cve/2012-3137>)
    * pickup the session key and salt for arbitrary users 
    * attack by dictionary on sessions 
  * the [ ** CVE-2012-???? ** ](<https://twitter.com/gokhanatil/status/595853921479991297>) : A user authenticated can modify all tables who can select even if he can’t modify them normally (no ALTER privilege). 
  * the [ ** CVE-2012-1675 ** ](<http://seclists.org/fulldisclosure/2012/Apr/204>) (aka TNS poisoning attack) ( ** NEW ** : 25/03/2016) 
  * ** search in column names ** thanks to the _ search _ module: 
  * search a pattern (ex: password) in column names 
  * ** unwrap ** PL/SQL source code (10g/11g and 12c) 
  * get ** system privileges ** and ** roles granted ** . It is possible to get privileges and roles of roles granted also ( ** NEW ** : 21/02/2016) 

![](https://d21ic6tdqjqnyw.cloudfront.net/wp-content/uploads/2018/02/23030510/ODAT_main_features_v2.0.jpg)

##  Supported Platforms and dependencies 

ODAT is compatible with ** Linux ** only. 

** Standalone versions ** exist in order to don’t have need to install dependencies and slqplus (see [ https://github.com/quentinhardy/odat/releases/ ](<https://github.com/quentinhardy/odat/releases/>) ). The ODAT standalone has been generated thanks to _ pyinstaller _ . 

If you want to have the ** development version ** installed on your computer, these following tools and dependencies are needed: 

  * Langage: Python 2.7 
  * Oracle dependancies: 
  * Instant Oracle basic 
  * Instant Oracle sdk 
  * Python libraries: 
  * cx_Oracle 
  * passlib 
  * pycrypto 
  * python-scapy 
  * colorlog (recommended) 
  * termcolor (recommended) 
  * argcomplete (recommended) 
  * pyinstaller (recommended) 

[ ![Oracle Database Attacking Tool: ODAT wiki](https://d21ic6tdqjqnyw.cloudfront.net/wp-content/uploads/2016/04/08083121/Wiki-e1516379207884.png) ](<https://github.com/quentinhardy/odat/wiki>)

[ ![Oracle Database Attacking Tool: ODAT Download](https://d21ic6tdqjqnyw.cloudfront.net/wp-content/uploads/2016/05/08082805/Download3-1024x154.png) ](<https://github.com/quentinhardy/odat>)