Oracle Security

Red-Database-Security GmbH
Latest trends in Oracle Security
Alexander Kornbrust30-Dec-2007
CCC - 24C3
Red-Database-Security GmbH
Few years ago Oracle was secure ;-)“Larry’s Unbreakable Campaign”
After starting this campaign the number of attacks against Oracleincreased heavily
But in the past just a few people were focusing on Oracle Security(Lichtfield, Cerrudo, Koret, Kornbrust, ...)
One of the milestones for Oracle Security was a PL/SQL unwrapper soldby a russian hacker. This guy was selling it to the usual securitycompanies.
After that the number of vulnerabilities in PL/SQL increased by 10 timesbecause the researchers were looking in PL/SQL source instead doingblack box tests with wrapped PL/SQL code
Oracle Security - PL/SQL - The Past
Red-Database-Security GmbH
 Oracle Security - PL/SQL - The Past - PL/SQL Unwrapper 

