TNSCMD10G
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
tnscmd10g communicates with Oracle TNS (Transparent Network Substrate) listener to extract information, check status, and enumerate Oracle database services. Updated version for 10g+.
BASIC USAGE#
tnscmd10g <command> -h <target> # Send TNS command to target tnscmd10g status -h <target> # Get listener status
COMMANDS#
tnscmd10g status -h <target> # Listener status/version info
tnscmd10g ping -h <target> # Ping TNS listener
tnscmd10g version -h <target> # Get listener version
tnscmd10g services -h <target> # List registered services
tnscmd10g debug -h <target> # Enable debug mode (if allowed)
tnscmd10g reload -h <target> # Reload listener config
tnscmd10g stop -h <target> # Stop listener (if allowed)
tnscmd10g rawcmd -h <target> -r <cmd>
# Send raw TNS command
OPTIONS#
tnscmd10g <command> -h <target> # Target hostname/IP
tnscmd10g <command> -p <port> # TNS port (default: 1521)
tnscmd10g <command> --rawcmd <data>
# Send raw command data
EXAMPLES#
# Get listener status and version tnscmd10g status -h 192.168.1.1 # Ping TNS listener tnscmd10g ping -h 192.168.1.1 # Get version on non-default port tnscmd10g version -h 192.168.1.1 -p 1522 # List registered services/SIDs tnscmd10g services -h 192.168.1.1
INFORMATION EXTRACTED#
# From status command: # - TNS Listener version # - Listener uptime # - Platform (OS) # - Registered SIDs/services # - ORACLE_HOME path # - Log file locations # - Security settings # - Trace file locations # From services command: # - Database SIDs # - Service names # - Instance names # - Service handlers
INTERPRETING STATUS OUTPUT#
# SECURITY = OFF → No password on listener (can be stopped!) # SECURITY = ON → Listener password set # SNMP = OFF/ON → SNMP management # Registered services list → Valid SIDs to target # The status output reveals: # - Operating system type # - Oracle version # - Database SID names # - Instance status (READY/BLOCKED)
NMAP ALTERNATIVE#
# Oracle TNS NSE scripts: nmap --script oracle-tns-version -p 1521 <target> nmap --script oracle-sid-brute -p 1521 <target> nmap --script oracle-brute -p 1521 <target> nmap -sV -p 1521 <target>
ATTACK WORKFLOW#
# 1. tnscmd10g status → get version, SIDs # 2. tnscmd10g services → enumerate services # 3. sidguesser → brute force additional SIDs # 4. oscanner → default password check # 5. sqlplus → connect with found credentials
NOTES#
- Perl-based tool - Updated for Oracle 10g+ TNS protocol - Default TNS Listener port: 1521 - Modern Oracle restricts status/services commands - "SECURITY = OFF" is a critical finding - SIDs revealed in status output are confirmed valid - Pair with oscanner and sidguesser - Only for authorized Oracle security auditing