Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 13:16:28 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1037680319&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2Fpapers%2Fdatabase%2Fcreate_any_directory_to_sysdba.pdf%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1037680319.1338210988.1338210988.1338210988.1%3B%2B__utmz%3D32867617.1338210988.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) create_any_directory_to_sysdba.pdf http://packetstormsecurity.org/files/70873/create_any_directory_to_sysdba.pdf http://packetstormsecurity.org/files/70873/create_any_directory_to_sysdba.pdf http://packetstormsecurity.org/files/70873/create_any_directory_to_sysdba.pdf.html Mon, 13 Oct 2008 22:37:23 GMT An Oracle DB user which has been granted CREATE ANY DIRECTORY can use that system privilege to grant themselves the SYSDBA system privilege by creating a DIRECTORY pointing to the password file location on the OS and then overwriting it with a previously prepared known binary password file using UTL_FILE.PUT_RAW from within the DB. This paper will show how the issue can be exploited and most importantly how to secure against it.