Metasploit mailing list archives

Re: admin/oracle/oracle_login undefined method


From: alfonso caponi <alfonso.caponi () gmail com>
Date: Wed, 30 Mar 2011 15:44:53 +0200

Ok mea culpa!!! The issue happens when I use a custom wordlist file. For
example:

doesn't works:

# file /trunk/data/wordlists/oracle_default_passwords_simple.csv
/trunk/data/wordlists/oracle_default_passwords_simple.csv: ASCII text

# cat /trunk/data/wordlists/oracle_default_passwords_simple.csv
Oracle,3,,,,blank user and blank pass
Oracle,3,SCOTT,TIGER,F894844C34402B67,This is a training account. It should
not be available in a production environment.
Oracle,3,ORACLE,ORACLE,38E38619A12E0257,

---------------------------------------------------

works:

# tail -n 10 /trunk/data/wordlists/oracle_default_passwords.csv >
/trunk/data/wordlists/test.csv

# file /trunk/data/wordlists/test.csv
/trunk/data/wordlists/test.csv: ASCII English text, with CRLF line
terminators

2011/3/30 Mario Ceballos <mc () metasploit com>

Alfonso,
 tested here and not able to reproduce.

~mc


On Wed, 30 Mar 2011, alfonso caponi wrote:

 Distributor ID: Ubuntu
Description:    Ubuntu 9.10
Release:        9.10
Codename:       karmic

ruby 1.8.7 (2009-06-12 patchlevel 174) [i486-linux]

oracle-instantclient-basic-10.2.0.4-1.i386
oracle-instantclient-devel-10.2.0.4-1.i386
oracle-instantclient-sqlplus-10.2.0.4-1.i386


-------------------------------------------------------------------------------------------
------

/trunk/msfcli admin/oracle/oracle_login RHOST=1.1.1.1 E

       =[ metasploit v3.7.0-dev [core:3.7 api:1.0]
+ -- --=[ 670 exploits - 350 auxiliary
+ -- --=[ 217 payloads - 27 encoders - 8 nops
       =[ svn r12182 updated today (2011.03.29)

RHOST => 1.1.1.1
[*] Starting brute force on 1.1.1.1:1521...
[-] Auxiliary failed: NoMethodError undefined method `downcase' for
nil:NilClass
[-] Call stack:
[-]   (eval):55:in `run'
[-]   /usr/lib/ruby/1.8/csv.rb:312:in `open_reader'
[-]   /usr/lib/ruby/1.8/csv.rb:532:in `parse'
[-]   /usr/lib/ruby/1.8/csv.rb:560:in `each'
[-]   /usr/lib/ruby/1.8/csv.rb:531:in `parse'
[-]   /usr/lib/ruby/1.8/csv.rb:311:in `open_reader'
[-]   /usr/lib/ruby/1.8/csv.rb:94:in `foreach'
[-]   (eval):53:in `run'
[*] Auxiliary module execution completed



_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: