Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 37 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » May 2005 » A great example of information leakage!

[Previous entry: "Richard talks about diagnostics support pack and applications collection tool (ACT)"] [Next entry: "Useful PL/SQL function that returns an MD5 sum for a string"]

A great example of information leakage!

May 10th, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

I just got an email from Tom Kyte to let me know about a link he had found on a blog listed on blogs.ittoolbox.com. The entry is titled "And You Thought Your Company Photos Were Bad?" and it says that a regular securitymonkey blog reader had sent this in.

The main item is a photo published in a magazine sent out by a UK train company. A close up of the photo reveals some great information goofs by showing usernames and passwords on a white board. This is a great example of how critical information can be leaked not just by newsgroup postings or on mailing lists. The key lesson to learn here is "why were the usernames and passwords on white board in the first place". This is not something new though. I have been in companies where similar info was listed on the walls on white boards.

Great blog post though.

May 2005
SMTWTFS
1234567
891011121314
15161718192021
22232425262728
293031    

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!