1521,1522-1529 - Pentesting Oracle TNS Listener

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

Oracle ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค(Oracle DB)๋Š” Oracle Corporation์˜ ๊ด€๊ณ„ํ˜• ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๊ด€๋ฆฌ ์‹œ์Šคํ…œ(RDBMS)์ž…๋‹ˆ๋‹ค(์—ฌ๊ธฐ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค here).

Oracle์„ ์—ด๊ฑฐํ•  ๋•Œ ์ฒซ ๋ฒˆ์งธ ๋‹จ๊ณ„๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ ๊ธฐ๋ณธ ํฌํŠธ(1521/TCP)์— ์œ„์น˜ํ•œ TNS-Listener์™€ ๋Œ€ํ™”ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค(1522โ€“1529์—์„œ ๋ณด์กฐ ๋ฆฌ์Šค๋„ˆ๋ฅผ ์–ป์„ ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค).

1521/tcp open  oracle-tns    Oracle TNS Listener 9.2.0.1.0 (for 32-bit Windows)
1748/tcp open  oracle-tns    Oracle TNS Listener

์š”์•ฝ

  1. ๋ฒ„์ „ ์—ด๊ฑฐ: ์•Œ๋ ค์ง„ ์ทจ์•ฝ์ ์„ ๊ฒ€์ƒ‰ํ•˜๊ธฐ ์œ„ํ•ด ๋ฒ„์ „ ์ •๋ณด๋ฅผ ์‹๋ณ„ํ•ฉ๋‹ˆ๋‹ค.
  2. TNS ๋ฆฌ์Šค๋„ˆ ๋ธŒ๋ฃจํŠธํฌ์Šค: ํ†ต์‹ ์„ ์„ค์ •ํ•˜๋Š” ๋ฐ ๋•Œ๋•Œ๋กœ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.
  3. SID ์ด๋ฆ„ ์—ด๊ฑฐ/๋ธŒ๋ฃจํŠธํฌ์Šค: ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์ด๋ฆ„(SID)์„ ๋ฐœ๊ฒฌํ•ฉ๋‹ˆ๋‹ค.
  4. ์ž๊ฒฉ ์ฆ๋ช… ๋ธŒ๋ฃจํŠธํฌ์Šค: ๋ฐœ๊ฒฌ๋œ SID์— ์ ‘๊ทผ์„ ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.
  5. ์ฝ”๋“œ ์‹คํ–‰: ์‹œ์Šคํ…œ์—์„œ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๋ ค๊ณ  ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.

MSF ์˜ค๋ผํด ๋ชจ๋“ˆ์„ ์‚ฌ์šฉํ•˜๋ ค๋ฉด ๋ช‡ ๊ฐ€์ง€ ์ข…์†์„ฑ์„ ์„ค์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค: ์„ค์น˜

๊ฒŒ์‹œ๋ฌผ

๋‹ค์Œ ๊ฒŒ์‹œ๋ฌผ์„ ํ™•์ธํ•˜์„ธ์š”:

HackTricks ์ž๋™ ๋ช…๋ น

Protocol_Name: Oracle    #Protocol Abbreviation if there is one.
Port_Number:  1521     #Comma separated if there is more than one.
Protocol_Description: Oracle TNS Listener         #Protocol Abbreviation Spelled out

Entry_1:
Name: Notes
Description: Notes for Oracle
Note: |
Oracle database (Oracle DB) is a relational database management system (RDBMS) from the Oracle Corporation

#great oracle enumeration tool
navigate to https://github.com/quentinhardy/odat/releases/
download the latest
tar -xvf odat-linux-libc2.12-x86_64.tar.gz
cd odat-libc2.12-x86_64/
./odat-libc2.12-x86_64 all -s 10.10.10.82

for more details check https://github.com/quentinhardy/odat/wiki

https://book.hacktricks.wiki/en/network-services-pentesting/1521-1522-1529-pentesting-oracle-listener.html

Entry_2:
Name: Nmap
Description: Nmap with Oracle Scripts
Command: nmap --script "oracle-tns-version" -p 1521 -T4 -sV {IP}

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ