Services Vulnerabilities Exploits Publications News Blog About DSecRG


We publish 3 new Oracle exploits

We happy to announce 3 new Oracle Database exploits for vulnerabilities from CPU April 2008. Advisory about this vulnerabilities was published by Esteban Martinez Fayo from Application Security. Brief text from advisory:

"Oracle Database provides the "LT" PL/SQL package that is part of the Oracle Workspace Manager component. This package has multiple instances of SQL Injection in COMPRESSWORKSPACETREE, MERGEWORKSPACE and REMOVEWORKSPACE procedures. Dependening on what Oracle Workspace Manager release is installed, this PL/SQL package is owned by SYS (on older releases) or by WMSYS (on newer releases). A malicious user can call the vulnerable procedures of this package with specially crafted parameters and execute SQL statements with the elevated privileges of the package owner, depending on the system configuration it can be SYS or WMSYS"

Our exploits not only give DBA rights to unprivileged user but also execute Operation System commands (creates new user) using 3 different methods.

1. SYS.LT.REMOVEWORKSPACE SQL Injection Exploit
Grant DBA and create new OS user using advanced extproc method which working in new database versions with updates.
2. SYS.LT.MERGEWORKSPACE SQL Injection Exploit
Grant DBA and create new OS user using java procedures.
3. SYS.LT.COMPRESSWORKSPACE SQL Injection Exploit
Grant DBA and create new OS user using database scheduler.

Exploits can be downloaded from our site or from milw0rm.com

News RSS RSS
11.08.2010
Source Barcelona 2010 Announcement

23.07.2010
CPU Updates from Oracle (CPU July 2010)

06.07.2010
DSecRG experts at Hack In The Box 2010 in Amsterdam

11.06.2010
DSECRG at CONFidence 2010

News list


© 2002—2010, Digital Security
For quoting or using materials from this site
link is obligatory

+7 (812) 703-1547, +7 (812) 430-9130    e-mail: research@dsecrg.com
Rss: Vulnerabilities, Exploits, News, Publications, Summary
Search