<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Oracle-Database on Ethical Hacking | Pentest e Sicurezza Informatica | Hackita</title><link>https://hackita.it/tags/oracle-database/</link><description>Recent content in Oracle-Database on Ethical Hacking | Pentest e Sicurezza Informatica | Hackita</description><generator>Hugo</generator><language>it</language><lastBuildDate>Thu, 06 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hackita.it/tags/oracle-database/index.xml" rel="self" type="application/rss+xml"/><item><title>Database Privilege Escalation: da Accesso DB a RCE</title><link>https://hackita.it/articoli/database-privilege-escalation/</link><pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate><guid>https://hackita.it/articoli/database-privilege-escalation/</guid><description>&lt;h1
 id="database-privilege-escalation-da-utente-db-a-rce-su-mssql-mysql-postgresql-e-oracle" class="group/anchor-heading"&gt;
 Database Privilege Escalation: da Utente DB a RCE su MSSQL, MySQL, PostgreSQL e Oracle
 &lt;a href="#database-privilege-escalation-da-utente-db-a-rce-su-mssql-mysql-postgresql-e-oracle" class="text-inherit opacity-0 group-hover/anchor-heading:opacity-100 decoration-transparent"&gt;#&lt;/a&gt;
&lt;/h1&gt;&lt;p&gt;Il &lt;strong&gt;database privilege escalation&lt;/strong&gt; è il processo con cui, partendo da un accesso al database (ottenuto tramite SQL injection, credenziali trovate, accesso diretto alla porta), si scala a un livello di privilegio superiore — fino a eseguire comandi sul sistema operativo sottostante.&lt;/p&gt;
&lt;p&gt;È uno dei path di escalation più comuni nei pentest su ambienti Windows e Linux: il database gira spesso come utente privilegiato (&lt;code&gt;SYSTEM&lt;/code&gt;, &lt;code&gt;root&lt;/code&gt;, &lt;code&gt;postgres&lt;/code&gt;), ed esistono funzionalità native pensate per l&amp;rsquo;amministrazione che diventano armi offensive nelle mani di un attaccante.&lt;/p&gt;</description></item></channel></rss>