Sie befinden sich aktuell in den Archiven des Blogs Alexander Kornbrust Oracle Security Blog für April, 2010.
- 11g (12)
- Allgemein (29)
- David Litchfield (7)
- Exploit (23)
- Forensics (7)
- Oracle Security (106)
- passwords (8)
- Repscan (1)
- Security (23)
- Sentrigo (5)
- software (9)
- source code audit (5)
- SQL Injection (24)
- Tools (24)
- Trainings (3)
- Tutorial (2)
- 9 Mrz 2012: 2 Cebit 2012 Presentations about Database Security
- 18 Nov 2011: DOAG 2011 Presentation "Best of Oracle Security 2011"
- 15 Okt 2011: Oracle Critical Patch Update Pre-Release Announcement - October 2011
- 17 Sep 2011: Disable Auditing and running OS commands using oradebug
- 13 Apr 2011: Blackhat Training "HACKING AND SECURING ORACLE (2 days) "
- 2 Apr 2011: Oracle Database 11.2 Express Edition Beta comes with weak default password
- 23 Mrz 2011: McAfee acquires Sentrigo
- 12 Okt 2010: TDE decrypt utilities and TDE/Password flash demo
- 22 Sep 2010: Marcell published "Writing your own password cracker" presentation
- 21 Sep 2010: Laszlo's presentation "Oracle Post Exploitation Techniques" and Marcel's Sybase ASE Password Cracker
Oracle Security
SQL Injection
- März 2012
- November 2011
- Oktober 2011
- September 2011
- April 2011
- März 2011
- Oktober 2010
- September 2010
- August 2010
- April 2010
- März 2010
- Februar 2010
- Januar 2010
- Dezember 2009
- November 2009
- Oktober 2009
- September 2009
- August 2009
- Juli 2009
- Mai 2009
- April 2009
- März 2009
- Februar 2009
- Januar 2009
- Dezember 2008
- November 2008
- Oktober 2008
- August 2008
- Juli 2008
- Mai 2008
- April 2008
- März 2008
- Februar 2008
- Januar 2008
- Dezember 2007
- November 2007
- Oktober 2007
- September 2007
- August 2007
- Juli 2007
- Juni 2007
- Mai 2007
Archive für April 2010
Improve Oracle TDE with Intel AES-NI
13 Apr 2010 von Alexander Kornbrust.
I found an interesting whitepaper “Securing the Enterprise with Intel AES-NI” from Intel.
This white paper explains how the new AES-NI instructions in Intel Xeon 5600 series can improve the AES encryption/decryption. When I read the first time about this feature I was impressed.
OpenSSL (AES part) is up to 7 times faster with this new instruction set.
Intel did also some tests with Oracle 11g and Transparent Data Encryption (TDE) in AES-256 CBC mode. The usage of the optimized Intel Integrated Performance Primitives (IPP) shows an 89 percent reduction (3.33 GHz Xeon X5680 vs 2.8 Intel Xeon X5560) against a previous processor.
This is a huge advantage and if you use TDE you should think about using such a new processor.
Geschrieben in Oracle Security | Drucken | Keine Kommentare »
Man-in-the-Middle attacks at upcoming Black Hat Europe
12 Apr 2010 von Alexander Kornbrust.
Wendel Guglielmetti Henrique and Steve Ocepek will demonstrate at the upcoming Black Hat Europe 2010 in Barcelona (14-15 April) how to steal credentials by downgrading authentication mechanisms as well as overtaking existing user sessions. They will also show their thicknet tool which will be available after the conference.
This sounds similar to Laszlo work on downgrading JDBC. But I had already a chance to review their presentation so I know it is different.
More information after their presentation.
Geschrieben in Tools, SQL Injection, Oracle Security | Drucken | Keine Kommentare »
Oracle CPU April 2010 - Prerelease
9 Apr 2010 von Alexander Kornbrust.
Yesterday Oracle released the CPU April 2010 Pre-Release. These patches will fix 47 security vulnerabilites. The database patch itself will contain 7 new security vulnerability fixes. None of these vulnerabilities are remote exploitable without authentication.
The highest CVSS base score for the Oracle database is 7.5.
The following components are affected:
• Change Data Capture
• Core RDBMS
• JavaVM
• Oracle XDB
• RDBMS Security
• XML DB
Oracle will fix one of my findings in the April 2010 CPU.
At the DOAG Expertenseminar “Oracle Hardening & Patching / Auditing & Co.” in Berlin (26.04.2010 - 27.04.2010) I will talk about this CPU as well. If you are interested you can attend this 2 day seminar.
Geschrieben in Oracle Security | Drucken | Keine Kommentare »
Cool Web Application Scanner: Netsparker Community Edition
8 Apr 2010 von Alexander Kornbrust.
Today I want to present the Netsparker Community Edition.
Netsparker (from Mavituna Security) is the best web application scanner I know. Easy to use and a really good web application scanning results. It saved me a lot of time and helped me to find security bugs in Oracle applications (Enterprise Manager).
The best thing: The new community edition is free (OK, with some limitations).
The commercial versions have even more interesting features like Time Based Blind SQL Injection, Remote Code Injection, OS Level Command Injection , CRLF / HTTP Header Injection / Response Splitting, …. The entire feature (and price) list is available here.
Here is a screenshot from Netsparker:
If you are interested just download the community edition.
Geschrieben in software, Security, Allgemein | Drucken | Keine Kommentare »
Joxean Koret released his presentation “Hackproofing Oracle Financials 11i / R12″
6 Apr 2010 von Alexander Kornbrust.
Joxean Koreat has released his presentation “Hackproofing Oracle Financials 11i / R12” from RootedCON 2010. Joxean shows some nice ways to own old and new Oracle Financials installations.
Thanks to Sid for the link via twitter.
Geschrieben in Oracle Security | Drucken | Keine Kommentare »
