
Database hole revealed...
By Sally Watson
Published: 4 July 2001 16:16 GMT
Hot on the heels of its reported weakness in its server software, Oracle has been left red-faced again today as security experts uncovered a hole in its 8i database.
According to researchers at the CERT lab in Carnegie Mellon University, a buffer overflow vulnerability in its flagship database software allows hackers remote control of the database server. On a Windows machine, the flaw could also allow intruders to wrest control of the underlying operating system.
Gunter Ollmann, principal consultant at ISS (Internet Security Systems) warned that the vulnerability is potentially very serious. "Anything which can give remote access to a system is not good," he pointed out.
With the help of some extra code, the vulnerability allows a malicious user to take over the privileges of the TNS listener process before authentication - so no username or password is required to gain access.
A standard internet firewall should protect most companies from external attackers, although Ollman warned that firms without firewall protection or with misconfigured software could be at risk. Even with a firewall, businesses remain at risk from malicious attacks within company walls.
Last month ISS discovered a similar flaw in Oracle Net8, leaving users of its hugely popular 7,8 and 8i databases open to external Denial of Service (DoS) attacks.
Ollman said: "It's such a large package with a tremendous amount of code. The bigger it is, the more likely it is that flaws will creep in."
Brands & technologies, and Vulnerability Network Scanners ( Nessus, nmap, Cybercop, ISS Internet Scanner). Candidates applying will have 4+ years of ...
Firewall Engineer, Berkshire, 34- 40k DOE + 10% Bonus + 10% Accreditation bonus We are a global leader in the provision and management of ...
You will also be responsible for building, configuring and deploying network hardware and applications, re-cabling, desk moves, management reporting ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business