[Previous entry: "Where's Larry? Ellison calls out sick at RSA Conference"] [Next entry: "Oracle 0-day exploit to be released - Blackhat Washington DC database security presentations"]
Argeniss are now selling Oracle rootkits!
February 12th, 2007 by Pete
Post to del.icio.us
Post to Furl
Alex pointed out a news item this evening titled "Oracle DB rootkit for sale in exploit pack" by Ryan Naraine
"A vulnerability research company in Argentina has fitted an Oracle database rootkit into its zero-day exploit pack, adding a stealthy new danger to enterprise systems.
The rootkit, which is available for sale in the Argeniss Ultimate 0day Exploits Pack, can be used to hide a malicious database user once a database server is compromised. The rootkit can also be used to hide activities that might set off alarm bells — running processes, opened connections, logins created, etc."
This is interesting. I can see how you may conclude that buying zero day exploits can be useful for manufactures of security tools so that they can test if their tools perform correctly in detecting any exploit that may occur, not just the known ones. A rootkit for Oracle though? I am not convinced there are any in the wild. I know Alex has talked about them at BlackHat and I have been aware of the idea of Oracle rootkits for much longer but I have not heard of one in the wild yet. There could be value for the same tool and product manufacturers in testing if audit tools can detect firstly a root kit and secondly a compromised system that includes a level of hiding using a root kit. The Oracle root kits that Alex has discussed are not honed and slick by any means (no disrespect to Alex intended) but I guess the security tools are also not honed to test for root kits yet. I have no idea of the complexity of the Argeniss rootkit but suspicions would be that it may fool some existing products but it would not fool someone who know how to check if one is installed.
Argeniss should share their research on this, or at least let us see the level of complexity of the rootkit. It would be useful in progressing free and commercial tools capabilities BUT it would also help develop more cunning Oracle root kits.
Interesting all the same!



February 15th, 2007 at 04:25 pm
Hamid.k says:
. simple but effective.
The rootkit released by Argeniss is based on few tricky modifications of SYS database , which makes oracle NOT to show details as they really are (jobs for example). The way rootkit make oracle to so so is not complex at all, but it`s based on simple tricks like modifying informations which oracle relays on, for showing details to DBA. and all these happens with 3 queries