Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 18 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » February 2006 » Andrew Clarke has a post about Google hacking Oracle

[Previous entry: "Security experts see vulnerabilities in embedded databases"] [Next entry: "Tom has a great post about continuity of operations"]

Andrew Clarke has a post about Google hacking Oracle

February 21st, 2006 by Pete

Post to del.icio.us   Post to Furl   Digg!

I saw today a post on Andrew's blog titled "Oracle...Most Insecure Database!" which relates the story of an Oracle forums post that is now not working, most likely removed!. The post talked about a person who had been reading an excellent paper on Application Security Inc's site titled "Search Engines used to attack databases" and then apparently applying what he had learned to hacking Oracle databases. Andrew had confirmed with the OP that he had in fact attacked his own Oracle databases.

This post prompted me to re-read Aaron's paper which is excellent.


February 2006
SMTWTFS
   1234
567891011
12131415161718
19202122232425
262728    

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!