Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 21 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » December 2004 » Niall has clarified the ODBC trace issue

[Previous entry: "Comments have been disabled from my weblog"] [Next entry: "A useful post on c.d.o.s about ADMIN_RESTRICTIONS_{listener_name}"]

Niall has clarified the ODBC trace issue

December 13th, 2004 by Pete

Post to del.icio.us   Post to Furl   Digg!

I posted a blog entry last week about the many possible techniques that could be used to audit the SQL that is sent from a black box application to the database server. This is where the source code is not available for the application. I posted the entry "Auditing the SQL a black box application submits to the database" where I said, amongst other things:

"I am (almost?) certain OBDC trace can be used as well. I need to investigate this option - assuming ODBC is used of course"

Niall emailed me at the end of last week to let me know that ODBC trace is not useful in grabbing the SQL sent from an application that uses ODBC. Niall told me the following:



  • It traces the ODBC calls and not the SQL itself - so you get lines like those listed at the end

  • It is unbelievably slow, I mean truly, awfully slow

  • I'm fairly sure that the original guy was using ADO which doesn't necessarily mean ODBC is involved anywhere




Thanks to Niall for the clarification on the ODBC issue.

For reference I also posted a second post on the subject of grabbing and auditing the SQL - This was called "Addendum to yesterdays auditing SQL from black box third party applications"

Finally Niall also made an additional post to the original thread on c.d.o.s today about ODBC that said:

"It is incredibly slow, and incredibly verbose. Those who bemoan the 'overhead' of timed_statistics=true or sql_trace ought to try it someday :("


December 2004
SMTWTFS
   1234
567891011
12131415161718
19202122232425
262728293031 

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!