Linuxϰ²×°MetasploitÆÆ½âOracleµÇ¼Óû§ÃûÃÜÂë
by:vitter@safechina.net
blog.securitycn.net
×î½üÔÚ¸ãoracle£¬Ò»Ð©Ð¡¶«Î÷¼Ç¼һÏ¡£
MetasploitÊÇÒ»¸öºÜºÃµÄ¹¥»÷¹¤¾ß°ü£¬µ±È»ÎÒÃÇÕâ´Î²»ÊǽéÉÜÕâ¸ö¹¤¾ß°üµÄ£¬Ö÷ÒªÊÇ´óÅ£MCдÁ˺ܶàoracleµÄ¹¤¾ß£¬ÔÚ×î½ü»á¾³£Óá£ÎÒÖ÷Òª»áÓõ½¾µä¹¤¾ßtnscmdÒÆÖ²µ½MSFÖеÄС¹¤¾ß£¨²»ÈçplµÄºÃÓã¬Ã»»»ÐУ¬¿´½á¹ûºÜÀÛ£©£¬sid_bruteºÍlogin_brute£¬ÓõÄ×î¶àµÄ»¹ÊDZ©Á¦ÆÆ½âoracleÓû§ÃûºÍÃÜÂëµÄlogin_brute¡£ÏÂÃæ¾Í˵ÏÂÔõô°²×°ºÍʹÓã¬Ö÷ÒªÊǰ²×°£¬ÒòΪÓÐЩÐèҪעÒâµÄ¶«Î÷£¬Çë×¢ÒâбÌå×Ö¡£
1¡¢ÏÈ×°gcc±àÒë»·¾³ £¨ÎÒÓõÄserver±È½Ï²Ò£¬×îС°²×°£¬ÏµÍ³Ò²ÀÏ£¬FC2¡££©
rpm -ivh cpp-3.3.3-7.i386.rpm
rpm -ivh glibc-kernheaders-2.4-8.44.i386.rpm
rpm -ivh glibc-headers-2.3.3-27.i386.rpm
rpm -ivh glibc-devel-2.3.3-27.i386.rpm
rpm -ivh binutils-2.15.90.0.3-5.i386.rpm
rpm -ivh gcc-3.3.3-7.i386.rpm
2¡¢°²×°oracle¿Í»§¶Ë
ÏÂÔØ£ºhttp://www.oracle.com/technology/software/tech/oci/instantclient/htdocs/linuxsoft.html
rpm°ü°²×°±È½ÏÊ¡ÊÂ,µ±È»ÄãÒ²¿ÉÒÔÏÂÔØÑ¹Ëõ°ü°²×°£¬°´ÕÕ˵Ã÷À´×°¼´¿É¡£
rpm -ivh oracle-instantclient11.1-basic-11.1.0.7.0-1.i386.rpm oracle-instantclient11.1-devel-11.1.0.7.0-1.i386.rpm oracle- instantclient11.1-sqlplus-11.1.0.7.0-1.i386.rpm
×°Íêºó£¬Ö´ÐÐÏÂÃæ2ÌõÃüÁͬʱÉèÖÃÔÚ»·¾³±äÁ¿À¼ÓÈëµ½/etc/profile×îºó¼´¿É£º
LD_LIBRARY_PATH=/usr/lib/oracle/11.1/client/lib/
export LD_LIBRARY_PATH
3¡¢×°ruby
ÏÂÔØ£ºhttp://www.ruby-lang.org/en/downloads/
tar zxvf ruby-1.8.5-p231.tar.bz2 #£¨Õâ¸ö×¢ÒâÏ£¬²»Òª×°1.9µÄ°æ±¾£¬·ñÔò»á³öÏÖMSF²»ÄܶÁCSVÎļþµÄÎÊÌâ,±¨NameError uninitialized constant CSV::Reader´íÎó£©
cd ruby-1.8.5-p231
./configure
make && make install
4¡¢×°ruby-oci8
°²×°ËµÃ÷£ºhttp://ruby-oci8.rubyforge.org/en/InstallForInstantClient.html
ÏÂÔØ£ºhttp://rubyforge.org/projects/ruby-oci8/
Õâ¸öruby-oci8-1.0.6°æ±¾»òÕß ruby-oci8-2.0.0¶¼¿ÉÒÔ¡£
°²×°Ç°ÒªÈ·ÈÏ»·¾³±äÁ¿£¬¼´sqlplusÄÜÕý³£ÔËÐоͿɣº
LD_LIBRARY_PATH=/usr/lib/oracle/10.2.0.3/client/lib
export LD_LIBRARY_PATH
tar zxvf ruby-oci8-2.0.0.tar.gz
cd ruby-oci8-2.0.0
make
make install
5¡¢×°ruby-dbi
ÏÂÔØ£ºhttp://rubyforge.org/frs/?group_id=234
ÓÃd
Ïà¹ØÎĵµ£º
¡¾IT168¼¼ÊõÎĵµ¡¿
DATA GUARDµÄ×îÖ÷ÒªµÄ¹¦ÄÜÊÇÈßÔÖ¡£µ±È»¸ù¾ÝÅäÖõIJ»Í¬£¬DATA GUARD»¹¿ÉÒԾ߱¸ÒÔÏÂÌØµã£º¸ß¿ÉÓá¢ÐÔÄÜÌáÉý¡¢Êý¾Ý±£»¤ÒÔ¼°¹ÊÕϻָ´µÈ¡£
DATA GUARD¿ÉÒÔ·ÖΪÎïÀíSTANDBYºÍÂß¼STANDBYÁ½ÖÖ¡£¶þÕßµÄ×î´ó²î±ðÔÚÓÚ£¬ÎïÀíSTANDBYÓ¦ÓõÄÊÇÖ÷¿âµÄ¹éµµÈÕÖ¾£¬¶øÂ ......
OracleϵÁУºÍ¼Æ¬µÄ´æ´¢
Ò»£ºÊ²Ã´ÊÇ´ó¶ÔÏ󣬴ó¶ÔÏó»ù±¾²Ù×÷£¿
²Î¼ûÎÒµÄBLOG£ºOracleϵÁУºLOB´ó¶ÔÏó´¦Àí
http://blog.csdn.net/qfs_v/archive/2008/05/21/2464599.aspx
¶þ£¬Í¼Æ¬µÄ´æ´¢»ò¶þ½øÖÆÎļþµÄ´æ´¢
1£¬ÏȲåÈëÆÕͨÊý¾Ý£¬Óöµ½´ó¶ÔÏóÁÐʹÓÃempty_blob()¹¹Ôì¿ÕµÄÖ¸Õë¡£
Àý× ......
Tablespace
ORACLEÖУ¬±í¿Õ¼äÊÇÊý¾Ý¹ÜÀíµÄ»ù±¾·½·¨£¬ËùÓÐÓû§µÄ¶ÔÏóÒª´æ·ÅÔÚ±í¿Õ¼äÖУ¬Ò²¾ÍÊÇÓû§ÓпռäµÄʹÓÃȨ£¬²ÅÄÜ´´½¨Óû§¶ÔÏó£®·ñÔòÊDz»³äÐí´´½¨¶ÔÏó£¬ÒòΪ¾ÍÊÇÏë´´½¨¶ÔÏó,Èç±í,Ë÷ÒýµÈ£¬Ò²Ã»Óеط½´æ·Å,Oracle»áÌáʾ:ûÓд洢Åä¶î£®
¡¡¡¡Òò´Ë£¬ÔÚ´´½¨¶ÔÏó֮ǰ£¬Ê×ÏÈÒª·ÖÅä´æ´¢¿Õ¼ä£®¡¡¡¡
·ÖÅä´æ ......
½ñÄêµÄOracleÈ«Çò´ó»áÓÚ10ÔÂ11ÈÕ£15ÈÕÔÚÃÀ¹ú¾É½ðɽµÄMosconeÖÐÐÄÒѾÀ¿ªÐòÄ»ÁË¡£
¡¡¡¡ Oracle¶ÔSun¹«Ë¾µÄ³¤ÆÚ¼Æ»®ÎÞÒÉÊDZ¾´ÎOOW´ó»áµÄ½¹µã¡£µ«ÔÚ̸ÂÛÕâ¸ö»°Ìâ֮ǰ£¬ÎÒÃÇ×¼±¸ÁËÒ»×é´ó»áµÄÓÐȤÊý¾Ý£¬ÏÈÈôó¼Ò¶Ô±¾´Î´ó»áÓиöÕûÌåµÄÓ¡Ïó¡£
¡¡¡¡ÓйØÕû¸ö´ó»áµÄÊý×Ö£º
¡¡¡¡· ½ü4.3ÍòÈ˵½»á
¡¡¡¡· ΪÃÀ¹ ......
ÎÒÃǶ¼¶¼ÖªµÀÔÚcontrolfileÖмǼ×Åÿһ¸öarchivelogµÄÏà¹ØÐÅÏ¢£¬µ±È»ÃÇÔÚOSϰÑÕâЩÎïÀíÎļþdeleteµôºó£¬ÔÚÎÒÃǵÄ
controlfileÖÐÈÔÈ»¼Ç¼×ÅÕâЩarchivelogµÄÐÅÏ¢£¬ÔÚoracleµÄOEM¹ÜÀíÆ÷ÖÐÓпÉÊÓ»¯µÄÈÕÖ¾Õ¹ÏÖ³ö£¬µ±ÎÒÃÇÊÖ¹¤Çå³ýarchiveĿ¼ÏµÄÎļþºó£¬ÕâЩ¼Ç¼²¢Ã»Óб»ÎÒÃÇ´ÓcontrolfileÖÐÇå³ýµô£¬Ò²¾ÍÊÇoracle²¢²» ......