Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 36 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » April 2005 » More insights to CPU 12 April and public exploit code

[Previous entry: "Esteban Martínez Fayó releases his security advisories for CPU 12 April"] [Next entry: "Frank has a good review of a secure coding book"]

More insights to CPU 12 April and public exploit code

April 19th, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

Alex has just emailed me to say that he has updated his paper "Comments on Oracle Critical Patch Update April 2005" to include clarifications of the patch pre-requisites. He has also added links to Application Security Inc's advisories and also more importantly he has included three examples of exploits from Esteban Mart�nez Fay� site.

These include an exploit to grant DBA to SCOTT by PL/SQL Injecting DBMS_METADATA. This can be found at http://www.argeniss.com/research/OraDBMS_METADATAExploit.txt. Also another exploit to grant DBA to SCOTT via the DBMS_CDC_SUBSCRIBE also by PL/SQL Injecting the package. This can be found at http://www.argeniss.com/research/OraDBMS_CDC_SUBSCRIBEExploit.txt and finally sample Denial of Service attacks via Intermedia which can be found at http://www.argeniss.com/research/OraIntermediaExploit.txt.

If you had not planned to apply this patch set quickly, you had better do so now!

April 2005
SMTWTFS
     12
3456789
10111213141516
17181920212223
24252627282930

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!