Tag: Oracle
-
Oracle Forensics von Litchfield
David Litchfield hat soeben auf verschiedenen Security Lists drei Paper zum Thema Oracle Forensics angekündigt: Oracle Forensics Part 1: Dissecting the Redo Logs Oracle Forensics Part 2: Locating Dropped Objects Oracle Forensics Part 3: Isolating Evidence of Attacks Against the Authentication Mechanism Paul M. Wright hat ebenfalls darauf aufmerksam gemacht, und hat auch schon einen…
-
Ich nicht er auch!
Wenn zwei dasselbe tun… so ist es noch lange nicht das gleiche. (Jemand bei) SAP hat tausende von Oracle Dokumenten und Produkten runtergeladen, mit dem Ziel, dass SAP billigeren Support für Oracle-Produkte leisten kann (sagt Oracle). Man ersetze mal Oracle mit Red Hat, und SAP mit Oracle, und erinnert sich plötzlich an die Geschichte mit…
-
Variation von GRANT DBA TO SCOTT
Wieso IDS nur eine von mehreren Security-Massnahmen sein können: Interesting Payload to PLSQL exploit at Milw0rm von Paul Wright. Instead of grant dba to scott the exploit payload inserts the values into sysauth$. This will bypass many IDS signatures. David mentioned this to me quite a while ago and it is now public so better…
-
BBED – Oracle Block Browser and EDitor: Kein Sicherheitsrisiko!
Pete Finnigan meint, dass BBED ein gefährliches Hackertool sei. BBED – Oracle Block Browser and EDitor – A hacker tool?: I […] even reported its shipping on Windows as an executable and as an object file on *nix as a security bug to Oracle around 4 years ago. Dann muss ich aber auch jedem DBA…
-
Oracle auf NFS
The Decommissioning of the Oracle Storage Certification Program von Kevin hat einen guten Teil über Oracle auf NFS. Das ist definitiv etwas, was wir uns mal genauer anschauen müssen, wenigstens für Entwickler-Systeme und die Small Apps Range von Datenbanken. Wie ich letzter Tage gehört habe, muss man NFS Filers verwenden anstatt das normale OS-Level NFS…
-
Oracle January 2007 CPU
Oracle hat gestern wie geplant das Oracle Critical Patch Update January 2007 angekündigt. Weitere Berichte von Eric Maurice, Manager for Security bei Oracle, und die Oracle January 2007 CPU Initial Thoughts von Integrigy. Seit dem Pre-Announcement wussten wir ja schon, dass es einzelne Security Bugs geben wird, die remote ohne Authentisierung ausgenutzt werden können, also…
-
Patch für VxFS mit Oracle 10.2.0.3
Die Aufregung war gross, als letzte Woche bekannt geworden ist, dass Oracle 10.2.0.3 nicht auf VxFS betreibbar ist. Jetzt ist ein One-Off-Patch verfügbar, aber die Schlamperei seitens Oracle scheint weiterzugehen, wie Kevin Closson schreibt. The 10.2.0.3 Patchset with VxFS Saga: An Example of Incorrectly Describing the Incorrectness: Since the Metalink note got it wrong by…
-
Januar CPU Preview Update
Kleine Presseschau 24 Stunden nach dem Announcement: Computerworld: Oracle will give early notice of security updates VNUNet: Oracle to issue pre-release patch info ZDNet: Oracle offering early warning on security fixes InfoWorld: Oracle now giving early notice of security updates Heise: Oracle führt Vorankündigung für eigenen Patchday ein The Register: Bullseye of Oracle patches due…
-
Oracle Critical Patch Update Pre-Release Announcement – January 2007
Oracle hat soeben sein Oracle Critical Patch Update Pre-Release Announcement – January 2007 veröffentlicht. Für die Datenbank selbst schreiben sie folgendes: This Critical Patch Update contains a total of 27 new security fixes for Oracle Database products, 10 of which may be remotely exploitable without authentication, i.e. they may be exploited over a network without…
-
How to Secure Oracle in 20 Minutes
Pete Finnigan hat eine nette Präsentation geschrieben zum Thema How to Secure Oracle in 20 Minutes: The paper […] makes the point that you cannot secure Oracle in 20 minutes but you can learn that you have a problem in 20 minutes and start to take action. The thing I learned from this is its…