| /// File Name: | create_any_directory_to_sysdba.pdf |
Description:
| An Oracle DB user which has been granted CREATE ANY DIRECTORY can use that system privilege to grant themselves the SYSDBA system privilege by creating a DIRECTORY pointing to the password file location on the OS and then overwriting it with a previously prepared known binary password file using UTL_FILE.PUT_RAW from within the DB. This paper will show how the issue can be exploited and most importantly how to secure against it. |
| Author: | Paul Wright |
| Homepage: | http://www.oracleforensics.com/ |
| Related Exploit: | createdirectory2sysdba.sql |
| File Size: | 430225 |
| Last Modified: | Oct 13 18:37:23 2008 |
| MD5 Checksum: | 404bf158718bb3d6e609975690deb646 |