Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 63 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » July 2009 » Hacking Oracle made easy

[Previous entry: "The right way to secure Oracle slides available"] [Next entry: "Bypassing VPD through inference"]

Hacking Oracle made easy

July 24th, 2009 by Pete

Post to del.icio.us   Post to Furl   Digg!

Chris Gates will release and demonstrate a new version of metaploit at Black Hat to show how Oracle can be attacked and hacked remotely. The presentation will be followed by the release of this version of Metasploit. Chris Gates demonstrated some of the ideas in February and he posted a video about this at that time - i mentioned it here at the time also.

The tool automates the attack against Oracle by first brute forcing/guessing the SID, then username/password and then by running various exploits.

There is a nice article also on Reuters talking about the presentation called "Hacking Oracle's database will soon get easier"

There has been 2 Comments posted on this article


July 24th, 2009 at 03:31 pm

CG says:

its actually just some auxiliary modules not a new version of metasploit.



July 27th, 2009 at 08:56 am

Pete Finnigan says:

Thanks for your comment Chris; yes i appreciated that it was new auxiliary modules; my words were really meant to convey that you are releasing the modules and it sounded easier to say its a new version, so that readers appreciate the specific new modules and the specific target that is relevant here.

Thanks Chris

cheers

pete


July 2009
SMTWTFS
   1234
567891011
12131415161718
19202122232425
262728293031 

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!