Study on Flaws Investigation and Privilege Escalation of Oracle

赵力涵,薛质,王轶骏
DOI: https://doi.org/10.3969/j.issn.1009-8054.2012.01.056
2012-01-01
Abstract:As a large database for business use, Oracle is widely-used in many multinational corporations and even government departments. So, many hackers attack Oracle for different purposes. For the mechanism that Oracle executes its own SQL procedure with different privileges, attackers could implement malicious functions or anonymous block created by themselves with SYS privilege. Thus the attackers could acquire DBA privilege and then implement full control on Oracle or even OS, this is a big challenge to Oracle database, and so Oracle has to continuously repair the old flaw. Thus how to continuously investigate the new flaw becomes the principal target of those attackers.
What problem does this paper attempt to address?