- 11g (5)
- Allgemein (15)
- checkpwd (4)
- CPUApril2009 (2)
- CPUJan2009 (3)
- David Litchfield (5)
- Exploit (12)
- Forensics (4)
- Oracle Security (65)
- passwords (5)
- Security (12)
- Sentrigo (5)
- software (6)
- source code audit (3)
- SQL Injection (15)
- Tools (10)
- Trainings (1)
- Tutorial (2)
- 16 Mai 2009: Presentation from Confidence 2009 available
- 1 Mai 2009: Perl - Script to run OS commands via Oracle based Web Apps released
- 23 Apr 2009: SQLMap 0.7 rc is out
- 21 Apr 2009: Listener Exploit (April 2009) from Dennis Yurichev published
- 20 Apr 2009: Whitepaper: Penetration from Application down to OS
- 20 Apr 2009: Pangolin 2.0.2.820 with enhanced Oracle support
- 16 Apr 2009: 3 new Oracle Security Videos
- 16 Apr 2009: SQL Injection Tool Pangolin 2.0 published
- 15 Apr 2009: Oracle Database Scanner Repscan 2.5 trial available
- 14 Apr 2009: Oracle Critical Patch Update April 2009 (CPUApr2009) is out
Oracle Security
Other Blogs
SQL Injection
Trainings
Impressions from HackInTheBox 2007 Malaysia
Just back from the biggest security conference “Hack In The Box” (HITB2007) in Asia. The conference took place in Kuala Lumpur in Malaysia. It was a really interesting conference and I met many interesting people and old friends like Stefano, FX, Sharan, David, Selwin, …
I gave a 2 day Oracle Anti-Hacker Training for people from all over the world and also a talk about “Hacking hardened and patched Oracle databases”. I will talk about my presentation (e.g. why the content of a create table “!rm -Rf /” is sometimes executed on OS level) in the next blog entry.
Here some lessons I learned at the conference:
1.) Microsoft saved my “Hacking Oracle” presentation because my MacBook Pro with Keynote 2008 was not working together with the projector (macs from other speakers were working). At the stage I had to convert the keynote presentation into powerpoint and to use my old laptop with windows to show my Oracle presentation.
2.) Asia Hackers are no thieves.
During the chaotic presentation (see 1.) I changed my laptops on the stage. Few hours later on the way to the airport I detected the I forgot the 3rd laptop. A short telephone call to the organizer Dhillon and a few minutes later I’ve got the message that the laptop (with full harddisk encryption) was still there.
It was a great conference…
Antwort schreiben
Sie müssen als angemeldet sein, um einen Kommentar schreiben zu können.
