Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 36 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » May 2005 » Red Database Security issues two new Oracle security advisories

[Previous entry: "A free script to find hidden users in your database"] [Next entry: "Alex has updated his Oracle exploits page to add 5 more exploit codes"]

Red Database Security issues two new Oracle security advisories

May 2nd, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

Today Alex Kornbrust has issued two new Oracle security advisories. These, like the last three issues on 26 May 2005 are not fixed as part of any Oracle released security advisory. Alex has found these two bugs in Metalink as part of his research for his "hacking metalink" article that is soon to be published. Alex has decided to publish these two advisories as the information for these bugs has been public for months. His Published Security Alerts page has been updated today 02-May-2005.

The first advisory "Fine Grained Auditing issue in Oracle 9i / 10g". The issue is where a SELECT is performed as SYS. There are two problems, the first is that the select statement as SYS is not audited and the second is that subsequent selects by any other user are also not audited. Alex goes on to show example code to demonstrate the issue. He also gives two workarounds, the first, do not run SQL on FGA objects as SYS and also flush the shared pool to activate auditing again. The second could give disadvantages to performance on the database.

The second advisory is "DBMS_SCHEDULER 10g SELECT user issue in Oracle 10g". This issue is that a user with CREATE JOB can run any job and after he has done so he has had the session_user switched to SYS. Alex gives example exploit code based on that available from metalink.

The big question is why were security advisories not made available from Oracle for these issues when they were fixed?

May 2005
SMTWTFS
1234567
891011121314
15161718192021
22232425262728
293031    

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!