Proof of concept worm targets Oracle databases

Powered by SC Magazine

An anonymous developer has published details of a proof-of-concept worm engineered to compromise Oracle databases which have been left with default user accounts and passwords.

According to a warning on the Full-Disclosure mailing list, the worm uses the UTL_TCP package to scan for remote Oracle databases on the same local network. Upon finding another database, the SID is retrieved and the worm uses several default username and password combinations to attempt to login to the remote database.

Currently, the worm's recorded default/username password list includes the following combinations: system/manager; sys/change_on_install; dbsnmp/dbsnmp; outln/outln; scott/tiger; mdsys/mdsys and ordcommon/ordcommon.

"When the worm discovers a default username and password, it creates a table "X" in the current user's schema with a date column called "Y". This could easily be changed to a more dramatic payload," warned the SANS Internet Storm Center.

In its current state, the worm is not deemed a "terribly significant" threat. However, security experts at SANs warned that data base administrators should treat the malware as "an early warning sign for future variants of the worm that include additional propagation methods".

Database security watcher Red Database Security agreed with this assessment: "The initial version of the worm must be started in the database manually but it is possible to use the glogin.sql feature of sqlplus to do this without the knowledge of the (database) user if it is possible to modify the file glogin.sql."

According to SANS, Oracle DBA's can take actions to mitigate the effect of this worm including changing the Oracle listener from the default port of TCP/1521 and setting a listener password.

Protection can also be enhanced by dropping or locking default user accounts where possible and ensuring that all default accounts do not use default passwords. Other precaution include revoking PUBLIC privileges to the UTL_TCP, UTL_INADDR packages and ensuring that CREATE DATABASE LINK privileges are not granted to users who do not need to link to remote databases.

Copyright © SC Magazine, US edition

Top Stories
Toll Group to go Google
Poaches Woolworths project manager.
How News Corp's CIO tackled skills in his race to the cloud
What to do when your team’s talents are no longer needed.
Photos: How Thodey transformed Telstra
From turbulent Trujillo to Australia's leading telco.
Sign up to receive iTnews email bulletins
Latest Comments
Who do you trust most to protect your private data?

   |   View results
Your bank
Your insurance company
A technology company (Google, Facebook et al)
Your telco, ISP or utility
A retailer (Coles, Woolworths et al)
A Federal Government agency (ATO, Centrelink etc)
An Australian law enforcement agency (AFP, ASIO et al)
A State Government agency (Health dept, etc)

Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
I DON'T support shutting the OAIC.