Calendar
April 2009
M D M D F S S
« Mrz   Mai »
 12345
6789101112
13141516171819
20212223242526
27282930  

Whitepaper: Penetration from Application down to OS

Few hours ago I saw that Paul Wright posted an entry on his blog Oracle Forensics about a whitepaper “Penetration from Application down to OS” from Alexandr Polyakov.

Alexandr explains in the well written document how to steal the Windows hashes using a fake SMB Server with low privileges (CONNECT, RESOURCE) via Oracle Text. On a previous blog entry in February “What is more dangerous? ALTER SESSION or OS Access?”  I showed how to read files via Oracle Text and Alexandr used a really smart approach to exploit this issue.

Well done Alexandr…

Antwort schreiben

Sie müssen als angemeldet sein, um einen Kommentar schreiben zu können.