Oracle Database Attacking Tool ODAT To Penetrate Oracle Database. Its an open source penetration testing tool that test Oracle database security as remotely. Its run on Linux platform.
You have an Oracle database listening remotely and want to find valid SIDs and credentials in order to connect to the database
You have a valid Oracle account on a database and want to escalate your privileges (ex: SYSDBA)
You have a valid Oracle account and want to execute commands on the operating system hosting this DB (ex: reverse shell)
Search valid SID on a remote Oracle Database listener via:
a dictionary attack
a brute force attack
ALIAS of the listener
Search Oracle accounts using:
a dictionary attack
each Oracle user like the password (need an account before to use this attack)
Execute system commands on the database server using:
DBMS_SCHEDULER
JAVA
external tables
oradbg
Download files stored on the database server using:
UTL_FILE
external tables
CTXSYS
Upload files on the database server using:
UTL_FILE
DBMS_XSLPROCESSOR
DBMS_ADVISOR
Delete files using:
UTL_FILE
Send/reveive HTTP requests from the database server using:
UTL_HTTP
HttpUriType
Scan ports of the local server or a remote server using:
UTL_HTTP
HttpUriType
UTL_TCP
Exploit the CVE-2012-313 (http://cvedetails.com/cve/2012-3137)
pickup the session key and salt for arbitrary users
attack by dictionary on sessions.
Development version installed on your computer, these following tool and dependencies are needed:
- Langage: Python 2.7
- Oracle dependencies
- Instant Oracle basic
- Instant Oracle sdk
- Python libraries
- cx_Oracle
- colorlog (recommended)
- termcolor (recommended)
- argcomplete (recommended)
- pyinstaller (recommended)
Download:




Post a Comment