Click to Play

Unleashed: Kelsey Ruger
WebProNews Reporter Abby Prince spoke with Kelsey Ruger, the Director of Technology and Creative Services of PopLabs, while at Small Business...

Recent Articles

The 451 Group's Database Report
I want to thank Matt Aslett & The 451 Group for being brave enough to publish this report on the impact of open source databases on the DB market. An excerpt...

IBM Joins List Of EnterpriseDB Investsors
EnterpriseDB just raised $10M in Series C financing. IBM joined the list of investors including Fidelity Ventures, Valhalla Partners and Charles River Ventures. To date, EnterpriseDB has raised $37.5M (compared to...

Google Analytics Adds Industry Benchmarking...
"We haven't used data and we will not use your data unless you opt-in," says Google Analytics' Brett Crosby. So, why would I start this post with that statement?

Where SOA, Rules, Processes And Events Come...
I missed the customer panel with Travelocity, Equifax, Deloitte Consulting and Bank of America but hopefully the DIABLOGgers got that one too (they did, check here).

04.30.08

New Oracle Hack

By Dan Morrill

Never assume anything, now you can't trust even typed data with oracle.

SQL injections are all over the Internet last week, and Security Researcher David Litchfield has published a paper on a new Oracle hack using date and number data types. The paper on the attack method can be found here and was published on Thursday. You can read the paper here.

In a SQL injection, attackers create specially crafted search terms that trick the database into running SQL commands. Previously, security experts thought that SQL injections would work only if the attacker was inputting character strings into the database, but Litchfield has shown that the attack can work using new types of data, known as date and number data types. Source: Computer World

There is a sense of irony here that databases and injection attacks are all the rage again, as databases in the past have seemingly gone through various iterations of being vulnerable since the acoustic modem was invented and people just didn't seem to put passwords on anything at all. Since then we have seen attacks against database systems culminating in the SQL Blaster, but now we are very deep into the whole idea of subverting exposed calls, and making those calls do neat and interesting things.

Learn More about what is Inside and Outside the Box

Oracle to date didn't have a specific hack, this is what makes Davids paper worth the read, the two data types, Number and Date previously were thought to not be an issue. The question though that should be perking up through the ranks is if Oracle which uses the same standards body as any relational database has this issue, is the same issue present in Microsoft SQL Server, IBM's database system and MySQL along with a number of smaller less used databases.

Read the paper, could be interesting in the longer run.

Comments


About the Author:
Dan Morrill has been in the information security field for 18 years, both civilian and military, and is currently working on his Doctor of Management. Dan shares his insights on the important security issues of today through his blog, Managing Intellectual Property & IT Security, and is an active participant in the ITtoolbox blogging community.
About DatabaseProNews
DatabaseProNews is a collection of articles, news and commentary designed to keep DBA's informed about the latest trends impacting their profession





DatabaseProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com DevWebPro.com





-- DatabaseProNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
© 2008 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


DatabasePronews News Archives About Us Feedback DatabaseProNews.com About Article Archive News Downloads WebProWorld Forums iEntry Advertise Contact