Skip to main content

David Litchfield slams Oracle database indexing

posted onJuly 27, 2012
by l33tdawg

A reactive approach to software security, namely following the security research community’s lead, has proven to be a winning strategy for Oracle Corp. in recent years.

Since 2008 the database giant has steadily trimmed the number of critical buffer-overflow vulnerabilities in the Oracle database server. Longtime thorn David Litchfield, however, may have forced Oracle to reassess its software security strategy after his talk Thursday at the 2012 Black Hat Briefings.

Litchfield demonstrated several working exploits against the Oracle database server’s indexing architecture, low-hanging fruit that Litchfield said has largely been ignored by attackers and Oracle—until now. Litchfield, one of the industry's top database security consultants, demonstrated several proof-of-concept attacks, during which he was able to elevate his privileges to the DBA level, giving him the ability to manipulate database indexing records remotely via SQL injection.

Source

Tags

Oracle Security Industry News

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th