AOH :: Oracle :: TB10193.HTM

0day Oracle 10g exploit - dbms_aq.enqueue - become DBA

0day Oracle 10g exploit - dbms_aq.enqueue - become DBA
0day Oracle 10g exploit - dbms_aq.enqueue - become DBA



[0-day] Remote Oracle DBMS_AQ.ENQUEUE exploit (10g)

Grant or revoke dba permission to unprivileged user
Tested on "Oracle Database 10g Enterprise Edition Release 10.1.0.3.0"
   
  AUTHOR: Andrea "bunker" Purificato
http://rawlab.mindcreations.com 

  DATE:   Mon Apr  2 11:54:22 CEST 2007
 
PATCH: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html 
          (CVE-2007-0268 ?)


You can find the evil code here: 
http://rawlab.mindcreations.com/codes/exp/oracle/dbms_aq-enqueue.pl 


Regards,
-- 
Andrea "bunker" Purificato
+++++++++++[>++++++>+++++++++++++++++++++++++++++++++>++++
++++++<<<-]>.>++++++++++.>.<----------.>---------.<+++++++.

http://rawlab.mindcreations.com 


The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2009 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.