← All cheat sheets

SIDGUESSER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

SIDGuesser (sidguess) guesses/brute-forces Oracle database SIDs
(System Identifiers). It connects to the Oracle TNS listener and
attempts to identify valid SIDs using a dictionary attack.

BASIC USAGE#

sidguess -i <target> -d <wordlist>
                                 # Brute force Oracle SIDs

OPTIONS#

sidguess -i <target>             # Target IP address
sidguess -p <port>               # TNS port (default: 1521)
sidguess -d <wordlist>           # SID dictionary file
sidguess -t <threads>            # Number of threads
sidguess -m                      # Manual SID test

EXAMPLES#

# Brute force SIDs with default wordlist
sidguess -i 192.168.1.1 -d sid.txt

# Custom port
sidguess -i 192.168.1.1 -p 1522 -d sid.txt

# Test specific SID manually
sidguess -i 192.168.1.1 -m ORCL

# Multi-threaded brute force
sidguess -i 192.168.1.1 -d sid.txt -t 5

COMMON ORACLE SIDs WORDLIST#

ORCL
XE
PROD
DEV
TEST
DB1
DB2
ORADB
ORCLCDB
ORAPROD
ORADEV
ORATEST
CDB
PDB
SAP
ERP
HR
FINANCE
APEX
CATALOG
RCAT
EMREP
SID1
SID2
OASDB
IASDB
GRIDCONTROL
MGMT
OEM
SCAN
ASM

SID DISCOVERY METHODS#

# 1. Dictionary brute force (sidguess)
sidguess -i <target> -d sid.txt

# 2. TNS listener enumeration
tnscmd10g status -h <target>

# 3. Nmap NSE scripts
nmap --script oracle-sid-brute -p 1521 <target>
nmap --script oracle-enum-users -p 1521 <target>

# 4. Metasploit
use auxiliary/scanner/oracle/sid_brute
set RHOSTS <target>
run

# 5. ODAT
odat sidguesser -s <target> -p 1521

# 6. Hydra
hydra -L sids.txt -s 1521 <target> oracle-sid

POST-SID DISCOVERY#

# After finding a valid SID:
# 1. Attempt default credentials
# 2. Try brute force login
# 3. Connect and enumerate

# Connect with sqlplus:
sqlplus user/pass@<target>:1521/<SID>

NOTES#

- TNS Listener must be accessible (port 1521)
- Some TNS configurations block SID brute force
- Modern Oracle may use Service Names instead of SIDs
- Account lockout policies may apply after login attempts
- Pair with oscanner for comprehensive Oracle auditing
- Consider ODAT for modern Oracle assessment
- Only for authorized security testing