Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 62 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » July 2005 » Internet News talks about Oracles latest Critical Patch Update

[Previous entry: "Grant talks about securing Forms applications with SSL"] [Next entry: "Oracle has been silently fixing security bugs in CPU July 2005"]

Internet News talks about Oracles latest Critical Patch Update

July 14th, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

I was looking around the net tonight at all the usual suspects looking for any new Oracle security news when I found another news story about the July CPU published today, 14 July, written by Jim Wagner and titled "Oracle Issues Critical Patch". This article starts with some facts gleaned from the CPU July advisory and then goes on to quote CERT's response to the patch set and advisory. There is then some very interesting discussions on Oracles non-disclosure policy and some comparisons are made with other manufacturers such as The Mozilla Foundation and also Microsoft. Michael Sutton is quoted as saying Oracle do not make it easy for customers to decide what to patch as there is not good enough information released to allow customers to decide whether to patch or not. He goes on further to talk about patch reverse engineering to find out what is fixed and that this method can be used to write exploits by hackers.

July 2005
SMTWTFS
     12
3456789
10111213141516
17181920212223
24252627282930
31      

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!