Oracle9i TSN DoS Attack

From: Andrey Gordienko (red@rsh.kiev.ua)
Date: 03/28/02


Date: 28 Mar 2002 10:54:07 -0000
From: Andrey Gordienko <red@rsh.kiev.ua>
To: bugtraq@securityfocus.com


('binary' encoding is not supported, stored as-is)

name : Oracle
date : 28/3/2002
description : Oracle9i TSN DoS Attack
severity : High risk
homepage : www.oracle.com
versions : 9.0.1.1 (another version may be too)
Bug description :
For crash Oracle9i you need sent ONE TCP packet
(#$00 = 1 byte) to 1521 port and you can fogot about
Oracle (CPU - 100%).You cant connect. For connect
to server you need restart TSNLISTEN.For use
expolit You DONT NEED Oracle client or any Oracle
dlls.
Solution: We sent message to oracle but we didnt
have answer
P.S. you can download win32 expolit from
www.safety-lab.com (ShadowDoSAnalyzer)

Safety-Lab www.safety-lab.com
RedShadow and Melcosoft



Relevant Pages

  • Re: obvious bugs with 10.2.0.2 and aix5L
    ... Gee why don't you list all of the bugs that, collectively, all of you ... Puget Sound Oracle Users Groupwww.psoug.org ... The main issue is that our execution plans have stayed the same but ... CPU) to handle our load. ...
    (comp.databases.oracle.server)
  • Re: Server unexpect shutdown
    ... Oracle 10.2.0.4 ... ACPI: Processor ... checking if CPU frequency changed. ... microcode: CPU0 already at revision 0x16 ...
    (comp.databases.oracle.server)
  • Re: AWR Sample Report
    ... Did you find that when it was set to TRUE Oracle was generating bad ... the introduction of CPU costing, which is enabled by default on Oracle ... Enables the enforcement of resource limits. ... although looking at an AWR report for a 31.2 second time period might ...
    (comp.databases.oracle.server)
  • Re: V$ Views
    ...  Remember, Oracle has its process id, while the OS has ... Oracle refers to a CPU TIME & ELAPSED TIME. ... ELAPSED TIME is the time the process has been running. ... The CPU statistic is reporting the actual CPU time to the nearest ...
    (comp.databases.oracle.misc)
  • Re: MEMORY ISSUE
    ... If your box starts swapping, I/O wait will be high as your disks are saturated with the task of swapping stuff in and out of RAM plus whatever non swap I/O you might be doing from other processes at the time. ... CPU states: cpu user nice system irq softirq iowait idle ... of the number of Oracle threads or other processes, ...
    (RedHat)