SIDGUESSER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
SIDGuesser (sidguess) guesses/brute-forces Oracle database SIDs (System Identifiers). It connects to the Oracle TNS listener and attempts to identify valid SIDs using a dictionary attack.
BASIC USAGE#
sidguess -i <target> -d <wordlist>
# Brute force Oracle SIDs
OPTIONS#
sidguess -i <target> # Target IP address sidguess -p <port> # TNS port (default: 1521) sidguess -d <wordlist> # SID dictionary file sidguess -t <threads> # Number of threads sidguess -m # Manual SID test
EXAMPLES#
# Brute force SIDs with default wordlist sidguess -i 192.168.1.1 -d sid.txt # Custom port sidguess -i 192.168.1.1 -p 1522 -d sid.txt # Test specific SID manually sidguess -i 192.168.1.1 -m ORCL # Multi-threaded brute force sidguess -i 192.168.1.1 -d sid.txt -t 5
COMMON ORACLE SIDs WORDLIST#
ORCL XE PROD DEV TEST DB1 DB2 ORADB ORCLCDB ORAPROD ORADEV ORATEST CDB PDB SAP ERP HR FINANCE APEX CATALOG RCAT EMREP SID1 SID2 OASDB IASDB GRIDCONTROL MGMT OEM SCAN ASM
SID DISCOVERY METHODS#
# 1. Dictionary brute force (sidguess) sidguess -i <target> -d sid.txt # 2. TNS listener enumeration tnscmd10g status -h <target> # 3. Nmap NSE scripts nmap --script oracle-sid-brute -p 1521 <target> nmap --script oracle-enum-users -p 1521 <target> # 4. Metasploit use auxiliary/scanner/oracle/sid_brute set RHOSTS <target> run # 5. ODAT odat sidguesser -s <target> -p 1521 # 6. Hydra hydra -L sids.txt -s 1521 <target> oracle-sid
POST-SID DISCOVERY#
# After finding a valid SID: # 1. Attempt default credentials # 2. Try brute force login # 3. Connect and enumerate # Connect with sqlplus: sqlplus user/pass@<target>:1521/<SID>
NOTES#
- TNS Listener must be accessible (port 1521) - Some TNS configurations block SID brute force - Modern Oracle may use Service Names instead of SIDs - Account lockout policies may apply after login attempts - Pair with oscanner for comprehensive Oracle auditing - Consider ODAT for modern Oracle assessment - Only for authorized security testing