Vulnerability in Oracle databases

Posted Feb 9, 2010 by Jane
David Litchfield seems to find that 9 out of 10 Oracle databases are vulnerable to hacker attacks that would give control over and access to information they contain without user names or passwords.
(UpVery.com) Feb 9, 2010 -- David Litchfield, a security expert, seems to find that 9 out of 10 Oracle databases are vulnerable to hacker attacks that would give control over and access to information they contain (including businesses and government agencies) without user names or passwords.

Litchfield works in the research sector NGSSoftware Ltd. (UK), and warned about the vulnerability to Oracle in November last year. However, several months later and in the absence of a solution by the makers of database software (the latest Oracle patch was released in January), decided to publish his discovery.

The important thing is that this vulnerability allows an attacker to take control of the database without user and password, and no firewall is being served. Although the exploit can be prevented by changing the program's default settings, Litchfield believes that 9 out of 10 databases are not ready to face a atque this style, and there is no way of knowing if it was used by someone.

What finish do not understand (and here you, dear readers, are more than welcome to give their view in the comments) is what is the need to make some of these flaws when the controller could not solve yet (reminds me of the case Windows a few weeks ago). Is not attract too much attention to something that can harm many users? One could argue that this puts pressure is responsible for the solution, but is it really the benefit outweighs the risk?

Meanwhile, Oracle does not make any public comments.

# # #

Trends: Database, Oracle, Security, vulnerability



Previous News: Google we love the Superbowl
Next News: Visualization of how it formed Twitter
UP:(0) | Hits:(19)
| More
Issued By Jane
Contact Email ***@gmail.com (Contact this user)
Country United States
Category Computers and Technology



Add Comments
Nickname: Required
Email: Required
Url: Option
Comment:
Image Text: Change another
© 2009-2010 Upvery.com All Rights Reserved Worldwide.