Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 20 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » April 2007 » Bunker has released a 0-day Oracle exploit

[Previous entry: "2 new exploits for Oracle"] [Next entry: "Argeniss have released a simple Oracle root kit"]

Bunker has released a 0-day Oracle exploit

April 2nd, 2007 by Pete

Post to del.icio.us   Post to Furl   Digg!

I saw today via Alex, Milw0rm and Bugtraq that Andrea "bunker" Purificato has released a new exploit in DBMS_AQ.ENQUEUE for 10gR1, version 10.1.0.3.0. The [0-day] Remote Oracle DBMS_AQ.ENQUEUE exploit (10g) is written in Perl and the example uses a payload of granting ALL PRIVILEGES and DBA to the supplied Oracle user account. I am a bit confused at the 0-day title as the post also includes a reference to the patch for the Jan CPU 2007 - CVE-2007-0268.

There has been 2 Comments posted on this article


April 2nd, 2007 at 09:48 pm

bunker says:

crazy Sorry for mistake. I meant "first public exploit" with word "0day"... hehe



April 3rd, 2007 at 06:02 pm

Pete says:

I guessed that was what you meant, thanks for the update.



April 2007
SMTWTFS
1234567
891011121314
15161718192021
22232425262728
2930     

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!