Anonymous SQL Execution in Oracle...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

A little over a year ago I was performing a penetration test on a client's external environment. One crucial step in any external penetration test is mapping out accessible web servers. The combination of nmap with EyeWitness make this step rather quick as we can perform port scanning for web servers and then feed those results into EyeWitness to get screenshots. After combing through pages of screenshots that EyeWitness produced, I came across a screenshot for an Oracle Advanced Support server. ![](https://images.seebug.org/1508896108864) Now, I have never heard of Oracle Advanced Support, but after some quick Googling it appeared to be a server that allows Oracle support to login externally and perform whatever support was needed on Oracle systems in an environment. With that in mind, let us put on our web app pentesting hat and walk through this together. Let's start with some simple recon on the application. This includes: * Searching for reported vulnerabilities * Spidering...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息