Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 42 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » June 2007 » Imperva launches a free database security scanner

[Previous entry: "Nice list of security papers"] [Next entry: "Database Vault presentation slides available"]

Imperva launches a free database security scanner

June 12th, 2007 by Pete

Post to del.icio.us   Post to Furl   Digg!

Imperva have launched a free database security scanner called Scuba. I have downloaded and tested the tool and whilst it has some teething troubles its a great tool not just because its free. Imperva via their ADC (Application Defence Center) will support the tool and add checks to it.

The tool supports Oracle, IBM DB2, MS SQL Server and Sybase. The tool is written in Java and employs a framework approach so adding new checks is done via an upgrade rather than a re-install.

I tested the tool locally against an Oracle database and got some results. There is a lot of Oracle checks, in excess of 100, some of which are old and I felt incorrect - in terms of results and also levels of severity. Also I was not enamoured by the registration process which failed for me! I sent some feedback to Imperva and they will take it on board, they have let me know that they will start a forum to allow feedback to be given more easily.

The tool is free though and its a good tool that wll get better with feedback and development. Get on over to Imperva and download it, its worth a look.

June 2007
SMTWTFS
     12
3456789
10111213141516
17181920212223
24252627282930

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!