Oracle
Scan
80 http IIS httpd 8.5
1521 oracle-tns 11.2.0.2.0 (unauthorized)
49160 oracletns listener (requires service name)nmap
nmap -Pn -n -sV -p1521 --script=oracle* 10.x.x.x -e tun0
PORT STATE SERVICE VERSION
1521/tcp open oracle-tns Oracle TNS listener 11.2.0.2.0 (unauthorized)
|
| oracle-sid-brute:
|_ XE hydra
hydra -L sids-oracle.txt -s 1521 10.10.10.82 oracle-sidOracle Client and ODAT Setup
Oracle SID
Oracle Pass
Login with sqlplus
ODAT Upload and Execute
ODAT (with MSF)
Read a File - with sqlplus
Make a File - with sqlplus
Make a Webshell - with sqlplus
Webshell: Reverse PowerShell
Enumerate the listener version
Last updated