This commit is contained in:
CoolHandSquid 2021-08-12 08:46:27 -04:00 committed by GitHub
parent e1cdfc3cdc
commit df5f9526b7
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -265,5 +265,31 @@ Other interesting **references**:
[http://blog.opensecurityresearch.com/2012/03/top-10-oracle-steps-to-secure-oracle.html](http://blog.opensecurityresearch.com/2012/03/top-10-oracle-steps-to-secure-oracle.html)
## HackTricks Automatic Commands
```
Protocol_Name: Oracle #Protocol Abbreviation if there is one.
Port_Number: 1521 #Comma separated if there is more than one.
Protocol_Description: Oracle TNS Listener #Protocol Abbreviation Spelled out
Name: Notes
Description: Notes for Oracle
Note: """
Oracle database (Oracle DB) is a relational database management system (RDBMS) from the Oracle Corporation
#great oracle enumeration tool
navigate to https://github.com/quentinhardy/odat/releases/
download the latest
tar -xvf odat-linux-libc2.12-x86_64.tar.gz
cd odat-libc2.12-x86_64/
./odat-libc2.12-x86_64 all -s 10.10.10.82
for more details check https://github.com/quentinhardy/odat/wiki
https://book.hacktricks.xyz/pentesting/1521-1522-1529-pentesting-oracle-listener
"""
Name: Nmap
Description: Nmap with Oracle Scripts
Command: """nmap --script "oracle-tns-version" -p 1521 -T4 -sV {IP}"""
```