knowledge is security
Showing 1 - 1 of 1 RSS Feed

Files

createdirectory2sysdba.sql
Posted Oct 13, 2008
Authored by Paul Wright | Site oracleforensics.com

Proof of concept code that demonstrates how an Oracle DB user which has been granted CREATE ANY DIRECTORY can use that system privilege to grant themselves the SYSDBA system privilege by creating a DIRECTORY pointing to the password file location on the OS and then overwriting it with a previously prepared known binary password file using UTL_FILE.PUT_RAW from within the DB.

tags | exploit, proof of concept
MD5 | 0aa995c9603c1c0edc67e8ed52f9a3d3
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close