<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.1" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Kommentare fuer Blog</title>
	<link>http://blog.red-database-security.com</link>
	<description></description>
	<pubDate>Sat, 05 Jul 2008 19:04:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.1</generator>

	<item>
		<title>Kommentar zu Oracle CPU April 2008 - Update von Alexander Kornbrust</title>
		<link>http://blog.red-database-security.com/2008/04/16/oracle-critical-patch-update-cpu-april-2008/#comment-6425</link>
		<author>Alexander Kornbrust</author>
		<pubDate>Mon, 16 Jun 2008 17:28:56 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/04/16/oracle-critical-patch-update-cpu-april-2008/#comment-6425</guid>
		<description>Hello zg,

I guess you mean privilege escalation. SQL Injection is always a security problem even if privilege escalation is not possible.

Even if AUTHID='CURRENT_USER' privilege escalation is sometimes possible, e.g. KUPW$WORKER, KUPM$MCP, ... have all AUTHID='CURRENT_USER' and are exploitable.

Hope this helps.

Regards

 Alexander</description>
		<content:encoded><![CDATA[<p>Hello zg,</p>
<p>I guess you mean privilege escalation. SQL Injection is always a security problem even if privilege escalation is not possible.</p>
<p>Even if AUTHID=&#8217;CURRENT_USER&#8217; privilege escalation is sometimes possible, e.g. KUPW$WORKER, KUPM$MCP, &#8230; have all AUTHID=&#8217;CURRENT_USER&#8217; and are exploitable.</p>
<p>Hope this helps.</p>
<p>Regards</p>
<p> Alexander</p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu Oracle CPU April 2008 - Update von &#62;zg</title>
		<link>http://blog.red-database-security.com/2008/04/16/oracle-critical-patch-update-cpu-april-2008/#comment-6424</link>
		<author>&#62;zg</author>
		<pubDate>Mon, 16 Jun 2008 16:52:13 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/04/16/oracle-critical-patch-update-cpu-april-2008/#comment-6424</guid>
		<description>I have a question,  how can we exploit injections like SDO_UTIL [DB05], SDO_GEOM [DB06] and SDO_IDX [DB07]   when they are defined with AUTHID CURRENT_USER ?</description>
		<content:encoded><![CDATA[<p>I have a question,  how can we exploit injections like SDO_UTIL [DB05], SDO_GEOM [DB06] and SDO_IDX [DB07]   when they are defined with AUTHID CURRENT_USER ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu Oracle Critical Patch Update April 2008 is out von Database Expert!</title>
		<link>http://blog.red-database-security.com/2008/04/15/oracle-critical-patch-update-april-2008-is-out/#comment-6262</link>
		<author>Database Expert!</author>
		<pubDate>Sun, 27 Apr 2008 11:43:50 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/04/15/oracle-critical-patch-update-april-2008-is-out/#comment-6262</guid>
		<description>Its cool article!</description>
		<content:encoded><![CDATA[<p>Its cool article!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu Looking Glass and Oracle 11g von Gary</title>
		<link>http://blog.red-database-security.com/2008/04/11/looking-glass-and-oracle-11g/#comment-5814</link>
		<author>Gary</author>
		<pubDate>Fri, 11 Apr 2008 21:17:10 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/04/11/looking-glass-and-oracle-11g/#comment-5814</guid>
		<description>Trying to work out the implications of this.
Useful articles are this one which explains what LookingGlass is about. 
http://erratasec.blogspot.com/2008/02/unsafe-at-anyspeed.html
and this one about complying with it
http://blogs.msdn.com/david_leblanc/archive/2008/03/14/use-of-aslr-nx-etc.aspx</description>
		<content:encoded><![CDATA[<p>Trying to work out the implications of this.<br />
Useful articles are this one which explains what LookingGlass is about.<br />
<a href="http://erratasec.blogspot.com/2008/02/unsafe-at-anyspeed.html" rel="nofollow">http://erratasec.blogspot.com/2008/02/unsafe-at-anyspeed.html</a><br />
and this one about complying with it<br />
<a href="http://blogs.msdn.com/david_leblanc/archive/2008/03/14/use-of-aslr-nx-etc.aspx" rel="nofollow">http://blogs.msdn.com/david_leblanc/archive/2008/03/14/use-of-aslr-nx-etc.aspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu We proudly present: Anna Marie Kornbrust von D. Nowak</title>
		<link>http://blog.red-database-security.com/2008/03/04/we-proudly-present-anna-marie-kornbrust/#comment-5662</link>
		<author>D. Nowak</author>
		<pubDate>Fri, 14 Mar 2008 12:04:35 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/03/04/we-proudly-present-anna-marie-kornbrust/#comment-5662</guid>
		<description>Congratulations,

to see a child grow is what realy matters...</description>
		<content:encoded><![CDATA[<p>Congratulations,</p>
<p>to see a child grow is what realy matters&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu We proudly present: Anna Marie Kornbrust von Slavik Markovich</title>
		<link>http://blog.red-database-security.com/2008/03/04/we-proudly-present-anna-marie-kornbrust/#comment-5633</link>
		<author>Slavik Markovich</author>
		<pubDate>Thu, 06 Mar 2008 15:08:26 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/03/04/we-proudly-present-anna-marie-kornbrust/#comment-5633</guid>
		<description>&lt;p&gt;Congratulations Alex, she is beautiful.&lt;br /&gt;
Slavik&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Congratulations Alex, she is beautiful.<br />
Slavik</p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu We proudly present: Anna Marie Kornbrust von Eric Grancher</title>
		<link>http://blog.red-database-security.com/2008/03/04/we-proudly-present-anna-marie-kornbrust/#comment-5629</link>
		<author>Eric Grancher</author>
		<pubDate>Tue, 04 Mar 2008 22:34:36 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/03/04/we-proudly-present-anna-marie-kornbrust/#comment-5629</guid>
		<description>congratulation, 
you daughter is beautiful 
(and the picture is well short)
eric</description>
		<content:encoded><![CDATA[<p>congratulation,<br />
you daughter is beautiful<br />
(and the picture is well short)<br />
eric</p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu We proudly present: Anna Marie Kornbrust von Joxean Koret</title>
		<link>http://blog.red-database-security.com/2008/03/04/we-proudly-present-anna-marie-kornbrust/#comment-5627</link>
		<author>Joxean Koret</author>
		<pubDate>Tue, 04 Mar 2008 17:58:39 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/03/04/we-proudly-present-anna-marie-kornbrust/#comment-5627</guid>
		<description>Congratulations Alex ;)</description>
		<content:encoded><![CDATA[<p>Congratulations Alex <img src='http://blog.red-database-security.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu First exploits for CPUJan2008 published von Joxean Koret</title>
		<link>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5059</link>
		<author>Joxean Koret</author>
		<pubDate>Fri, 01 Feb 2008 21:14:04 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5059</guid>
		<description>Sorry for the typo: 

&#62;Many of these were reported to 3rd parties (iDefense and ZDI).

Many "others" were reported to 3rd parties.

Joxean Koret</description>
		<content:encoded><![CDATA[<p>Sorry for the typo: </p>
<p>&gt;Many of these were reported to 3rd parties (iDefense and ZDI).</p>
<p>Many &#8220;others&#8221; were reported to 3rd parties.</p>
<p>Joxean Koret</p>
]]></content:encoded>
	</item>
	<item>
		<title>Kommentar zu First exploits for CPUJan2008 published von Joxean Koret</title>
		<link>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5057</link>
		<author>Joxean Koret</author>
		<pubDate>Fri, 01 Feb 2008 21:12:08 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5057</guid>
		<description>Hi Alex,

I have 23 currently unfixed flaws in Oracle Database (taken, as you, from the secalert report). But that number only reflects the total vulnerabilities I reported directly. Many of these were reported to 3rd parties (iDefense and ZDI).

Joxean Koret</description>
		<content:encoded><![CDATA[<p>Hi Alex,</p>
<p>I have 23 currently unfixed flaws in Oracle Database (taken, as you, from the secalert report). But that number only reflects the total vulnerabilities I reported directly. Many of these were reported to 3rd parties (iDefense and ZDI).</p>
<p>Joxean Koret</p>
]]></content:encoded>
	</item>
</channel>
</rss>
