[Previous entry: "Hacking Oracle, but not in English"] [Next entry: "11i Security papers available"]
More on Oracle hacking techniques
February 23rd, 2007 by Pete
Post to del.icio.us
Post to Furl
I posted about the Blackhat DC conference that is coming up soon a few days ago in a post titled "Oracle 0-day exploit to be released - Blackhat Washington DC database security presentations" and talked about David Litchfields presentation and surmised what it may be about. Well David will talk about a new Oracle attack vector that involves dangling cursors and will show how a user with only CREATE SESSION privileges can execute any SQL, PL/SQL or DDL in the database. This is quite a cool attack technique.


