← All cheat sheets

TNSCMD10G

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

tnscmd10g communicates with Oracle TNS (Transparent Network
Substrate) listener to extract information, check status, and
enumerate Oracle database services. Updated version for 10g+.

BASIC USAGE#

tnscmd10g <command> -h <target>  # Send TNS command to target
tnscmd10g status -h <target>     # Get listener status

COMMANDS#

tnscmd10g status -h <target>     # Listener status/version info
tnscmd10g ping -h <target>       # Ping TNS listener
tnscmd10g version -h <target>    # Get listener version
tnscmd10g services -h <target>   # List registered services
tnscmd10g debug -h <target>      # Enable debug mode (if allowed)
tnscmd10g reload -h <target>     # Reload listener config
tnscmd10g stop -h <target>       # Stop listener (if allowed)
tnscmd10g rawcmd -h <target> -r <cmd>
                                 # Send raw TNS command

OPTIONS#

tnscmd10g <command> -h <target>  # Target hostname/IP
tnscmd10g <command> -p <port>    # TNS port (default: 1521)
tnscmd10g <command> --rawcmd <data>
                                 # Send raw command data

EXAMPLES#

# Get listener status and version
tnscmd10g status -h 192.168.1.1

# Ping TNS listener
tnscmd10g ping -h 192.168.1.1

# Get version on non-default port
tnscmd10g version -h 192.168.1.1 -p 1522

# List registered services/SIDs
tnscmd10g services -h 192.168.1.1

INFORMATION EXTRACTED#

# From status command:
# - TNS Listener version
# - Listener uptime
# - Platform (OS)
# - Registered SIDs/services
# - ORACLE_HOME path
# - Log file locations
# - Security settings
# - Trace file locations

# From services command:
# - Database SIDs
# - Service names
# - Instance names
# - Service handlers

INTERPRETING STATUS OUTPUT#

# SECURITY = OFF           → No password on listener (can be stopped!)
# SECURITY = ON            → Listener password set
# SNMP = OFF/ON            → SNMP management
# Registered services list → Valid SIDs to target

# The status output reveals:
# - Operating system type
# - Oracle version
# - Database SID names
# - Instance status (READY/BLOCKED)

NMAP ALTERNATIVE#

# Oracle TNS NSE scripts:
nmap --script oracle-tns-version -p 1521 <target>
nmap --script oracle-sid-brute -p 1521 <target>
nmap --script oracle-brute -p 1521 <target>
nmap -sV -p 1521 <target>

ATTACK WORKFLOW#

# 1. tnscmd10g status → get version, SIDs
# 2. tnscmd10g services → enumerate services
# 3. sidguesser → brute force additional SIDs
# 4. oscanner → default password check
# 5. sqlplus → connect with found credentials

NOTES#

- Perl-based tool
- Updated for Oracle 10g+ TNS protocol
- Default TNS Listener port: 1521
- Modern Oracle restricts status/services commands
- "SECURITY = OFF" is a critical finding
- SIDs revealed in status output are confirmed valid
- Pair with oscanner and sidguesser
- Only for authorized Oracle security auditing