oracle²ÎÊýnls_length_semantics£º
ĬÈÏ£ºbyte
create table test (a varchar(20),b number)
µÈͬÓÚ£º
CREATE TABLE HXG.TESTNLS
(
A VARCHAR2(20 BYTE),
B NUMBER
)
varchar(20)ÓɲÎÊýnls_length_semantics¿ØÖÆ
////////////////////////////////////////////////////////////////
CREATE TABLE HXG.TESTNLS
(
A VARCHAR2(20 BYTE),
B NUMBER
)
CREATE TABLE HXG.TESTNLS
(
A VARCHAR2(20 char),
B NUMBER
) ......
Oracle sqlplusÔ¶³ÌÁ¬½ÓÊý¾Ý¿â
sqlplus username/password@yunSID_192.168.1.5
¹«Ë¾Ê¹ÓÃlinux¿ª·¢»ú½øÐгÌÐò¿ª·¢Ê±£¬ÓÉÓÚ¿ª·¢ÓÃOracleÊý¾Ý¿âÊÇÓÉÈÕ·½Ìṩ£¬ËùÒÔ¾³£Ê¹ÓÃsqlplusÁ¬½Óµ½Ô¶³ÌÊý¾Ý¿âÉϽøÐпª·¢,ÀýÈ磺
sqlplus username/password@servicename
ÓÚÊÇÏ룬ÓÃÎÒµÄÁ½Ì¨µçÄÔË«»ú»¥ÁªÊÔÒ»ÊÔ£¬Ò²Íæ¸ö“Ô¶³ÌÁ¬½Ó”¡£ÊµÑéÈçÏ£º
Ê×ÏÈÔÚÎÒµĄ̈ʽ»úÉϰ²×°ÁËOracle9iµÄÊý¾Ý¿â¹ÜÀíϵͳ£¬²¢½¨Á¢ÁËÒ»¸öÊý¾Ý¿âʵÀý£ºxy
È»ºóΪ¸ÃʵÀýÐÂÔöÁËÒ»¸öÓû§£¬Óû§ÃûºÍÃÜÂë¶¼ÊÇkxy01¡£Æô¶¯ÊµÀýxyºó£¬ÔŲ́ʽ»úÉÏ£¬Ö±½ÓÔÚcmd»·¾³¼üÈ룺sqlplus kxy01/kxy01@xy ¾Í¿ÉÒÔÁ¬½ÓÉÏÊý¾Ý¿â£¬ºÇºÇ£¬ÏëÀ´±¾µØÁ¬½Ó¶¼ÊDz»·Ñ´µ»ÒÖ®Á¦¾ÍÐеġ£
Ö®ºó£¬ÔÚÎҵıʼDZ¾Éϰ²×°ÁËOracle9iµÄClient¹¤¾ß¡£È»ºóÊÔ×ÅÖ±½ÓÓÃÉÏÊöÃüÁî·ÃÎÊ£¬ÏÔÈ»ÊDz»Ðеģ¬ÏµÍ³·µ»ØÎÞ·¨½âÎö·þÎñÃûµÄ´íÎóÐÅÏ¢¡£
ҪʵÏÖÁ¬½Óµ½Ô¶³ÌÊý¾Ý¿â£¬ÏÈÁ˽âÒ»ÏÂÏà¹ØÖªÊ¶°É£¬²éÁËÒ»ÏÂÊé¡£ÔÀ´£¬OracleÊý¾Ý¿âµÄÔ¶³ÌÁ¬½ÓÊÇͨ¹ýOracle NetʵÏֵġ£ÔÚ·þÎñÆ÷ºÍ¿Í»§¶Ë¶¼±ØÐëÔËÐÐÓÐÅäÖÃÕýÈ·µÄOracle Net²Å¿ÉÒÔ¡£²»¹ÜʹÓõÄÅäÖúÍÅäÖù¤¾ßÈçºÎ£¬¶¼Ó¦¸Ã¸æËßOracle NetÔõÑùÕÒµ½Ô¶³ÌÊý¾Ý¿â¡£
ÒªÔõôÅäÖÃOracle NetÄØ¡£µã¿ªOracleµÄ¿ªÊ¼²Ëµ ......
¸úÆäËûÓïÑԵIJÎÊý²î²»¶à£¬Ê¹ÓÃʱҪ°Ñ°ÑÕæÊµÊý¾Ý´«¹ýÈ¥Ìæ´ú
Óŵã¼ÇµÃһЩ£¬Èç¹ûÔÚ²éѯÖÐʹÓÃÖ±½ÓÁ¿£¨³£Á¿£©£¬ÄÇôÿ¸ö²éѯ¶¼½«ÊÇÒ»¸öȫеIJéѯ£¬±ØÐë¶Ô²éѯ½øÐнâÎö¡¢ÏÞ¶¨£¨ÃüÃû½âÎö£©¡¢°²È«ÐÔ¼ì²é¡¢ÓÅ»¯µÈ¼´ÖØÐÂÉú³ÉÖ´Ðмƻ®¡£¶øÊ¹ÓÃÁËÒÔºó¾Í¿ÉÒÔÖØ¸´Ê¹ÓÃ×îÏÈ´´½¨µÄÖ´Ðмƻ®¡£ ......
¶ÔÓÚ×°ºÃÁ˸ÃÈí¼þºó,ÀûÓÃsystemÊÇÄܵǽøÈ¥µÄ,»ú×ÓÖØÆôºó,³öÏֵĸÃÎÊÌ⣺
¿ÉÄÜÄú ÔËÐÐ--sqlplusw ÊÇÄܵÇÉÏÈ¥µÄ ¶ø»»³ÉPL/SQL Developer È´Á¬²»ÉÏ ·þÎñÆ÷,Èç¹ûÄúÈ·¶¨ÄãµÄ·þÎñ¿ªÆôÁË
ËÑË÷ÕÒµ½tnsnames.oraºÍlistener.oraÎļþ, °ÑÆäÖеÄHOST=ºóµÄÖ÷»úÃû»òip¸ÄΪµ±Ç°µÄÖ÷»úÃû»òip£¬²¢ÖØÐÂÆô¶¯¼àÌý·þÎñ¡£Ö®ºóˢпØÖÆÌ¨Ò³Ã棬»á¿´µ½¼àÌý³ÌÐòÒѾÆô¶¯£¬µ«¿ÉÄÜ»á³öÏÖÏÂÃæµÄÌáʾ“ORA-12505: TNS: ¼àÌý³ÌÐòµ±Ç°ÎÞ·¨Ê¶±ðÁ¬½ÓÃèÊö·ûÖÐËù¸ø³öµÄ SID (DBD ERROR: OCIServerAttach)”£¬Ã»¹ØÏµ£¬¶àˢм¸´Î¼´¿É¿´µ½µ½ÊµÀýµÄ´úÀíÁ¬½Ó³É¹¦µÄÐÅÏ¢¡£ ......
###author:hiphop###
###qq:70381908###
ΪʲôҪ¹Ø×¢ Oracle ?
ÒòΪOracle ±»´óÁ¿ÆóÒµËùʹÓÃ,ÓÐÐí¶àÄ¿±ê¿ÉÒÔÑ¡ÔñÀ´ÉøÍ¸
Ðí¶àÆóÒµ¶¼Ã»ÓиüÐÂÇÒÓÐDZÔڵķ½ÏÕ!
ÌáȨ·Ç³£¼òµ¥,ÈÝÒ×Äõ½shell!!
¶ÁÁËblackhat paper ÈÃÎÒ¿ªÊ¼À´Ñо¿Oracle
ÒòΪËûÖ»½²µ½Ò»Ð¡²¿·Ý ÕæÕý°²È«ÎÊÌ⻹ÓкܹãµÄ
Ö»ÊǹúÄÚºÃÏñºÜÉÙÍÚ¾ò
ÒòΪÓöµ½µÄ»·¾³²»¶à
µ«Êǰ¢ Oracle ÊÇ free download ºÇºÇ
¸¶·Ñ²Å¿ÉÒÔupgrade
Ò»°ãÁ¬½Ó Oracle ÐèÒªÒÔϼ¸¸öÌõ¼þ£º
IP
PORT
SID
username/password
The Oracle listener default port is 1521
generally in the 1521-1540 range
ɨÃè´Ì̽²»»á¸úÄã˵ÓÃʲô°æ±¾µ«Ð°æµÄnmap ¿ÉÒÔÈ¡µÃµ½Ò»Ð©,ʹÓÃTNS packet¿ÉÒÔ½â¾öÕâ¸öÎÊÌâ
TNS packet ¿ÉÒÔÁ˽â oracle °æ±¾
SID ´Ì̽·½Ê½:
1.TNS listener directly
2.brute force for default sid
3.query other component ¿ÉÄܰüº¬ÓÐSID
u/p ÆÆ½â
ÌáȨ·½·¨:
Ìá權 1 java function
Win32Exec
Ìá權2 smbrelay
Run OS commands via sql injection in web applications
Run OS commands via create table
Run OS commands via dbms scheduler
Run OS commands via PL/SQL and Extproc
Run OS ......
import java.net.url;
import java.sql.*;
public class javaoracle {
public javaoracle() {
}
public static void main(string[] args){
try
{
try{
class.forname("oracle.jdbc.driver.oracledriver");
}
catch(java.lang.classnotfoundexception e)
{
system.err.print(e.getmessage());
}
string url="jdbc:oracle:thin:@server:1521:sdcdb";
connection conn=drivermanager.getconnection(url,"test","test");
statement stmt=conn.createstatement();
resultset rs=stmt.executequery("select score from my");
while(rs.next())
{
system.out.println(rs.getstring(1));
}
conn.close();
}
catch(sqlexception ex)
{
while(ex!=null)
{system.out.println(ex.getsqlstate());
}
}
}
}
///////////////////////
ÔÚtry{}ÖУº Class.forName("oracle.jdbc.driver.OracleDriver");
//½«OracleDriverÔØÈë ......
import java.net.url;
import java.sql.*;
public class javaoracle {
public javaoracle() {
}
public static void main(string[] args){
try
{
try{
class.forname("oracle.jdbc.driver.oracledriver");
}
catch(java.lang.classnotfoundexception e)
{
system.err.print(e.getmessage());
}
string url="jdbc:oracle:thin:@server:1521:sdcdb";
connection conn=drivermanager.getconnection(url,"test","test");
statement stmt=conn.createstatement();
resultset rs=stmt.executequery("select score from my");
while(rs.next())
{
system.out.println(rs.getstring(1));
}
conn.close();
}
catch(sqlexception ex)
{
while(ex!=null)
{system.out.println(ex.getsqlstate());
}
}
}
}
///////////////////////
ÔÚtry{}ÖУº Class.forName("oracle.jdbc.driver.OracleDriver");
//½«OracleDriverÔØÈë ......