- Alexander Kornbrust Oracle Security Blog - http://blog.red-database-security.com -

New russian Oracle exploit tool “Oracle Security Tools” (updated)

Dieser Eintrag stammt von Alexander Kornbrust Am 13 Nov 2009 @ 21:39 In Tools, Exploit | Kommentarfunktion deaktiviert

During my research on Russian websites I found a new security tool called “[1] Oracle Security Tools“. This tool offers different methods to exploit Oracle databases.

Oracle Security Tools

Here is a list of features

  • The privileges escalation of the Oracle users;
  • The verification of system accounts concerning the existence of a default password;
  • Account compliance test of login=password
  • The execution of the PL/SQL code;
  • The privileges escalation in the OS Windows 2000/XP/2003 (add a local user as root and holder of remote connection powers);
  • The infiltration into the OS and the execution of DOS-commands, holding the administrative rights.
  • Viewing the users’ connections to the database and their activity;
  • Analyse the external TNS listener.log;

After checking the executable on [2] virustotal I run the program on one of my test VMwares. After switching the russian interface to the english interface I not able to run the tool. I always got the error message:

It seems to be a problem with my vmware system and the mulitple Oracle Homes. After switching to another computer the program was working without problems.


Dieser Artikel wurde ausgedruckt ab Alexander Kornbrust Oracle Security Blog: http://blog.red-database-security.com

URL zum Artikel: http://blog.red-database-security.com/2009/11/13/new-russian-oracle-exploit-tool-oracle-security-tools/

URLs in this post:
[1] Oracle Security Tools: http://securetools.ru/en/tools.php
[2] virustotal: http://www.virustotal.com/de/analisis/1342676f1cc53794ca5dd4bd133ff3db3d1435f611
4322e1e36a5a48271d5021-1256494267

Klicken hier zum Drucken.