Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 23 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » March 2007 » Cesar Cerrudo shows how to find more than 5 local 0-days in Oracle

[Previous entry: "Site downtime"] [Next entry: "2 new exploits for Oracle"]

Cesar Cerrudo shows how to find more than 5 local 0-days in Oracle

March 29th, 2007 by Pete

Post to del.icio.us   Post to Furl   Digg!

Cesar Cerrudo spoke at the recent Blackhat Federal conference in Washington with a paper titled "Practical 10 Minute Security Audit: The Oracle Case" which describes how to soend 10 minutes and a few free tools to find at least 5 local 0-days in Oracle. These tools are Process Explorer, WinObj from SysInternals and pipaclTools from bindview. Cesar also includes a white paper of the same name and also an Oracle exploit. The paper is not bad, the bugs are all local so exploiting them would be limited to those with local access and as I said the other day they are all related to NULL DACL issues which David spoke about on the Oracle-L list last year and also in his recent book.

The value in the presentation though is the fact that free tools can be still used to find security bugs in Oracle (and indeed in any software), this indicates that the battle is not over by any means for Oracle, they may be on top of the SQL Injection to some extent but they need to make headway on the core issues in the software. I wonder if Fortify finds these types of issues?


March 2007
SMTWTFS
    123
45678910
11121314151617
18192021222324
25262728293031

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!