Calendar
April 2008
M D M D F S S
« Mrz   Mai »
 123456
78910111213
14151617181920
21222324252627
282930  

Looking Glass and Oracle 11g

Yesterday I read an article about Apple Quicktime and LookingGlass. I downloaded the free tool from the website of errata security.

Here are the results from a test with Oracle 11.1.0.6 on Windows. I have scanned the Oracle Home and the tool found 518 Oracle files with dangerous functions like strcpy, sprintf, sscanf, strcat, …

Output Looking Glass

The Oracle executable (oracle.exe) for example is using wsprintfA, strncpy, sprintf, sscanf, _vsnprintf, _snprintf, vprintf, strncat, strtok, strlen, strcpy, strcat.

1 Antwort auf “Looking Glass and Oracle 11g”

  1. Gary sagt:

    Trying to work out the implications of this.
    Useful articles are this one which explains what LookingGlass is about.
    http://erratasec.blogspot.com/2008/02/unsafe-at-anyspeed.html
    and this one about complying with it
    http://blogs.msdn.com/david_leblanc/archive/2008/03/14/use-of-aslr-nx-etc.aspx

Antwort schreiben