|
490 | 490 | <getPrivileges value="True"/>
|
491 | 491 | <getRoles value="True"/>
|
492 | 492 | <getDbs value="True"/>
|
493 |
| - <getTables value="True"/> |
494 | 493 | <getColumns value="True"/>
|
495 | 494 | <getCount value="True"/>
|
496 | 495 | <dumpTable value="True"/>
|
497 |
| - <db value="scott"/> |
| 496 | + <db value="sys"/> |
498 | 497 | <tbl value="users"/>
|
499 | 498 | <excludeSysDbs value="True"/>
|
500 | 499 | </switches>
|
|
508 | 507 | <item value="current user is DBA: True"/>
|
509 | 508 | <item value="r'database management system users \[.+ANONYMOUS.+SCOTT.+SYS.+XDB'"/>
|
510 | 509 | <item value="r'database management system users password hashes:.+CTXSYS \[.+password hash: D1D21CA56994CAB6.+clear-text password: ORACLE.+DBSNMP \[.+password hash: E066D214D5421CCC.+clear-text password: DBSNMP.+SYS \[.+password hash: 2D5A0C491B634F1B.+clear-text password: TESTPASS'"/>
|
511 |
| - <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ADMINISTER ANY SQL TUNING SET'"/> |
512 |
| - <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+JAVA_DEPLOY'"/> |
513 |
| - <item value="r'available databases \[.+CTXSYS.+SCOTT.+WMSYS'"/> |
514 |
| - <item value="r'Database: SCOTT.+ tables.+USERS'"/> |
515 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
516 |
| - <item value="r'Database: SCOTT.+Table.+Entries.+USERS.+5'"/> |
517 |
| - <item value="r'Database: SCOTT.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
| 510 | + <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ALTER ANY EVALUATION CONTEXT'"/> |
| 511 | + <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+XDBADMIN'"/> |
| 512 | + <item value="r'available databases \[.+CTXSYS.+MDSYS.+SYSTEM'"/> |
| 513 | + <item value="r'Database: SYS.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
| 514 | + <item value="r'Database: SYS.+Table.+Entries.+USERS.+5'"/> |
| 515 | + <item value="r'Database: SYS.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
518 | 516 | </parse>
|
519 | 517 | </case>
|
520 | 518 | <case name="Oracle error-based multi-threaded enumeration - all entries">
|
|
537 | 535 | <getColumns value="True"/>
|
538 | 536 | <getCount value="True"/>
|
539 | 537 | <dumpTable value="True"/>
|
540 |
| - <db value="scott"/> |
| 538 | + <db value="sys"/> |
541 | 539 | <tbl value="users"/>
|
542 |
| - <excludeSysDbs value="True"/> |
543 | 540 | <answers value="do you want to perform a dictionary-based attack against retrieved password hashes=N"/>
|
544 | 541 | </switches>
|
545 | 542 | <parse>
|
|
552 | 549 | <item value="current user is DBA: True"/>
|
553 | 550 | <item value="r'database management system users \[.+ANONYMOUS.+SCOTT.+SYS.+XDB'"/>
|
554 | 551 | <item value="r'database management system users password hashes:.+CTXSYS \[.+password hash: D1D21CA56994CAB6.+DBSNMP \[.+password hash: E066D214D5421CCC.+SYS \[.+password hash: 2D5A0C491B634F1B'"/>
|
555 |
| - <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ADMINISTER ANY SQL TUNING SET'"/> |
556 |
| - <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+JAVA_DEPLOY'"/> |
557 |
| - <item value="r'available databases \[.+CTXSYS.+SCOTT.+WMSYS'"/> |
558 |
| - <item value="r'Database: SCOTT.+ tables.+USERS'"/> |
559 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
560 |
| - <item value="r'Database: SCOTT.+Table.+Entries.+USERS.+5'"/> |
561 |
| - <item value="r'Database: SCOTT.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
| 552 | + <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ALTER ANY EVALUATION CONTEXT'"/> |
| 553 | + <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+XDBADMIN'"/> |
| 554 | + <item value="r'available databases \[.+CTXSYS.+MDSYS.+SYSTEM'"/> |
| 555 | + <item value="r'Database: SYS.+ tables.+USERS'"/> |
| 556 | + <item value="r'Database: SYS.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
| 557 | + <item value="r'Database: SYS.+Table.+Entries.+USERS.+5'"/> |
| 558 | + <item value="r'Database: SYS.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
562 | 559 | </parse>
|
563 | 560 | </case>
|
564 | 561 | <case name="Oracle UNION query multi-threaded enumeration - all entries">
|
|
581 | 578 | <getColumns value="True"/>
|
582 | 579 | <getCount value="True"/>
|
583 | 580 | <dumpTable value="True"/>
|
584 |
| - <db value="scott"/> |
| 581 | + <db value="sys"/> |
585 | 582 | <tbl value="users"/>
|
586 |
| - <excludeSysDbs value="True"/> |
587 | 583 | <answers value="do you want to perform a dictionary-based attack against retrieved password hashes=N"/>
|
588 | 584 | </switches>
|
589 | 585 | <parse>
|
|
596 | 592 | <item value="current user is DBA: True"/>
|
597 | 593 | <item value="r'database management system users \[.+ANONYMOUS.+SCOTT.+SYS.+XDB'"/>
|
598 | 594 | <item value="r'database management system users password hashes:.+CTXSYS \[.+password hash: D1D21CA56994CAB6.+DBSNMP \[.+password hash: E066D214D5421CCC.+SYS \[.+password hash: 2D5A0C491B634F1B'"/>
|
599 |
| - <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ADMINISTER ANY SQL TUNING SET'"/> |
600 |
| - <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+JAVA_DEPLOY'"/> |
601 |
| - <item value="r'available databases \[.+CTXSYS.+SCOTT.+WMSYS'"/> |
602 |
| - <item value="r'Database: SCOTT.+ tables.+USERS'"/> |
603 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
604 |
| - <item value="r'Database: SCOTT.+Table.+Entries.+USERS.+5'"/> |
605 |
| - <item value="r'Database: SCOTT.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
| 595 | + <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ALTER ANY EVALUATION CONTEXT'"/> |
| 596 | + <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+XDBADMIN'"/> |
| 597 | + <item value="r'available databases \[.+CTXSYS.+MDSYS.+SYSTEM'"/> |
| 598 | + <item value="r'Database: SYS.+ tables.+JOBS.+REGIONS'"/> |
| 599 | + <item value="r'Database: SYS.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
| 600 | + <item value="r'Database: SYS.+Table.+Entries.+USERS.+5'"/> |
| 601 | + <item value="r'Database: SYS.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
606 | 602 | </parse>
|
607 | 603 | </case>
|
608 | 604 | <case name="Oracle partial UNION query multi-threaded enumeration - all entries">
|
|
625 | 621 | <getColumns value="True"/>
|
626 | 622 | <getCount value="True"/>
|
627 | 623 | <dumpTable value="True"/>
|
628 |
| - <db value="scott"/> |
| 624 | + <db value="sys"/> |
629 | 625 | <tbl value="users"/>
|
630 |
| - <excludeSysDbs value="True"/> |
631 | 626 | <answers value="do you want to perform a dictionary-based attack against retrieved password hashes=N"/>
|
632 | 627 | </switches>
|
633 | 628 | <parse>
|
|
640 | 635 | <item value="current user is DBA: True"/>
|
641 | 636 | <item value="r'database management system users \[.+ANONYMOUS.+SCOTT.+SYS.+XDB'"/>
|
642 | 637 | <item value="r'database management system users password hashes:.+CTXSYS \[.+password hash: D1D21CA56994CAB6.+DBSNMP \[.+password hash: E066D214D5421CCC.+SYS \[.+password hash: 2D5A0C491B634F1B'"/>
|
643 |
| - <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ADMINISTER ANY SQL TUNING SET'"/> |
644 |
| - <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+JAVA_DEPLOY'"/> |
645 |
| - <item value="r'available databases \[.+CTXSYS.+SCOTT.+WMSYS'"/> |
646 |
| - <item value="r'Database: SCOTT.+ tables.+USERS'"/> |
647 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
648 |
| - <item value="r'Database: SCOTT.+Table.+Entries.+USERS.+5'"/> |
649 |
| - <item value="r'Database: SCOTT.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
| 638 | + <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ALTER ANY EVALUATION CONTEXT'"/> |
| 639 | + <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+XDBADMIN'"/> |
| 640 | + <item value="r'available databases \[.+CTXSYS.+MDSYS.+SYSTEM'"/> |
| 641 | + <item value="r'Database: SYS.+ tables.+JOBS.+REGIONS'"/> |
| 642 | + <item value="r'Database: SYS.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
| 643 | + <item value="r'Database: SYS.+Table.+Entries.+USERS.+5'"/> |
| 644 | + <item value="r'Database: SYS.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
650 | 645 | </parse>
|
651 | 646 | </case>
|
652 | 647 | <case name="Oracle time-based single-threaded enumeration - all entries">
|
|
683 | 678 | <getColumns value="True"/>
|
684 | 679 | <getCount value="True"/>
|
685 | 680 | <dumpTable value="True"/>
|
686 |
| - <db value="scott"/> |
| 681 | + <db value="sys"/> |
687 | 682 | <tbl value="users"/>
|
688 |
| - <excludeSysDbs value="True"/> |
689 | 683 | <answers value="do you want to perform a dictionary-based attack against retrieved password hashes=N"/>
|
690 | 684 | </switches>
|
691 | 685 | <parse>
|
|
698 | 692 | <item value="current user is DBA: True"/>
|
699 | 693 | <item value="r'database management system users \[.+ANONYMOUS.+SCOTT.+SYS.+XDB'"/>
|
700 | 694 | <item value="r'database management system users password hashes:.+CTXSYS \[.+password hash: D1D21CA56994CAB6.+DBSNMP \[.+password hash: E066D214D5421CCC.+SYS \[.+password hash: 2D5A0C491B634F1B'"/>
|
701 |
| - <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ADMINISTER ANY SQL TUNING SET'"/> |
702 |
| - <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+JAVA_DEPLOY'"/> |
703 |
| - <item value="r'available databases \[.+CTXSYS.+SCOTT.+WMSYS'"/> |
704 |
| - <item value="r'Database: SCOTT.+ tables.+USERS'"/> |
705 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
706 |
| - <item value="r'Database: SCOTT.+Table.+Entries.+USERS.+5'"/> |
707 |
| - <item value="r'Database: SCOTT.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
| 695 | + <item value="r'database management system users privileges:.+CTXSYS.+ALTER SESSION.+ SYS .+ALTER ANY EVALUATION CONTEXT'"/> |
| 696 | + <item value="r'database management system users roles:.+MDSYS.+CONNECT.+SYS \(administrator\).+DBA.+XDBADMIN'"/> |
| 697 | + <item value="r'available databases \[.+CTXSYS.+MDSYS.+SYSTEM'"/> |
| 698 | + <item value="r'Database: SYS.+ tables.+JOBS.+REGIONS'"/> |
| 699 | + <item value="r'Database: SYS.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
| 700 | + <item value="r'Database: SYS.+Table.+Entries.+USERS.+5'"/> |
| 701 | + <item value="r'Database: SYS.+Table: USERS.+5 entries.+luther.+nameisnull.+'"/> |
708 | 702 | </parse>
|
709 | 703 | </case>
|
710 | 704 | <case name="SQLite boolean-based multi-threaded enumeration - all entries">
|
|
963 | 957 | <tech value="E"/>
|
964 | 958 | <getSchema value="True"/>
|
965 | 959 | <dumpTable value="True"/>
|
966 |
| - <db value="scott"/> |
| 960 | + <db value="sys"/> |
967 | 961 | <tbl value="users"/>
|
968 | 962 | <limitStart value="2"/>
|
969 | 963 | <limitStop value="4"/>
|
970 | 964 | <excludeSysDbs value="True"/>
|
971 | 965 | </switches>
|
972 | 966 | <parse>
|
973 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
974 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 entries.+fluffy.+bunny.+wu.+ming'"/> |
| 967 | + <item value="r'Database: SYS.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
| 968 | + <item value="r'Database: SYS.+Table: USERS.+3 entries.+fluffy.+bunny.+wu.+ming'"/> |
975 | 969 | </parse>
|
976 | 970 | </case>
|
977 | 971 | <case name="Oracle UNION query multi-threaded custom enumeration">
|
|
981 | 975 | <tech value="U"/>
|
982 | 976 | <getSchema value="True"/>
|
983 | 977 | <dumpTable value="True"/>
|
984 |
| - <db value="scott"/> |
| 978 | + <db value="sys"/> |
985 | 979 | <tbl value="users"/>
|
986 | 980 | <limitStart value="2"/>
|
987 | 981 | <limitStop value="4"/>
|
988 | 982 | <excludeSysDbs value="True"/>
|
989 | 983 | </switches>
|
990 | 984 | <parse>
|
991 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
992 |
| - <item value="r'Database: SCOTT.+Table: USERS.+3 entries.+fluffy.+bunny.+wu.+ming'"/> |
| 985 | + <item value="r'Database: SYS.+Table: USERS.+3 columns.+SURNAME.+VARCHAR2'"/> |
| 986 | + <item value="r'Database: SYS.+Table: USERS.+3 entries.+fluffy.+bunny.+wu.+ming'"/> |
993 | 987 | </parse>
|
994 | 988 | </case>
|
995 | 989 | <case name="Oracle boolean-based multi-threaded custom enumeration - substring">
|
|
998 | 992 | <threads value="4"/>
|
999 | 993 | <tech value="B"/>
|
1000 | 994 | <dumpTable value="True"/>
|
1001 |
| - <db value="scott"/> |
| 995 | + <db value="sys"/> |
1002 | 996 | <tbl value="users"/>
|
1003 | 997 | <firstChar value="3"/>
|
1004 | 998 | <lastChar value="5"/>
|
1005 | 999 | </switches>
|
1006 | 1000 | <parse>
|
1007 |
| - <item value="r'Database: SCOTT.+Table: USERS.+5 entries.+the | iss.+<blank> | mei'"/> |
| 1001 | + <item value="r'Database: SYS.+Table: USERS.+5 entries.+the | iss.+<blank> | mei'"/> |
1008 | 1002 | </parse>
|
1009 | 1003 | </case>
|
1010 | 1004 | <case name="SQLite UNION query multi-threaded custom enumeration">
|
|
0 commit comments