USLANMAM
USLANMAM öğesini iGoogle sayfanıza ekleyin.
UslanmaM En Kaliteli Bilgi Adresiniz
Geri git   USLANMAM > HABERLER > English News > Technology News
Google
 
UslanmaM Resim AlbümleriSosyal Gruplar
Kayıt ol Sosyal Gruplar Ajanda Konuları Okundu Kabul Et

Technology News Technology news for enterprise IT from InfoWorld

Yeni Konu aç  Cevapla
 
LinkBack Seçenekler Stil
Alt 09-04-2007, 02:30 PM   #1 (permalink)
Yeni Üye
 
USLANMAM - ait Kullanıcı Resmi (Avatar)
Standart Expert finds 'stupid' holes in Oracle 11g

(Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın) - The latest version of:-)Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın offers better security than earlier versions but development errors have left vulnerabilities that attackers can use to steal data an expert warned Monday.
Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın
"Oracle made big progress with 11g but some of the vulnerabilities I've found so far in 11g are stupid programming errors" said Alexander Kornbrust managing director of Red Database Security GmbH during an interview at the Hack In The Box (HITB) Security Conference 2007 in Kuala Lumpur Malaysia.
"Oracle must educate their own development team because they should normally avoid these simple security vulnerabilities" Kornbrust said.
Oracle executives were not immediately available for comment.
Kornbrust who helps large companies audit the security of their Oracle databases examined the software and found SQL injection vulnerabilities which allow attackers to run malicious code. He also uncovered a way to circumvent the auditing capability in 11g and other versions of the database which could undermine a company's compliance efforts.
While Kornbrust plans to discuss some Oracle vulnerabilities at HITB he has no plans to detail his method for bypassing the auditing capability until Oracle has fixed the problem.
Some of the problems that Kornbrust uncovered reflect architectural problems with Oracle's database. In a talk scheduled for later this week he plans to demonstrate how architectural problems allow attackers to "bypass and avoid" Oracle's latest security tools including Oracle Database Vault and Oracle Audit Vault.
The cost and time required to fix a vulnerability in Oracle's database can be staggering because of the critical role the software plays in the business of large companies and the wide range of platforms that Oracle supports Kornbrust said.
Citing the example of one German company that has 8000 Oracle databases Kornbrust said rolling out a single aaaaa can require 32000 hours of labor or four hours per database. That translates into 60 aaaa-time database administrators and doesn't take into account the time and expense required for testing the aaaaa on each database he said.
Moreover for each vulnerability that gets aaaaaed Oracle must develop a aaaaa for every version of its database that's supported with a version of each for every hardware platform and operating system the database runs on. That amounts to around 100 separate aaaaaes for every vulnerability Kornbrust said.
HITB runs through Sept. 6.


Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın

USLANMAM isimli Üye şimdilik offline konumundadır  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Alıntı ile Cevapla

Cevapla


Konuyu Toplam 1 Üye okuyor. (0 Kayıtlı üye ve 1 Misafir)
 
Seçenekler
Stil

Yetkileriniz
You may not post new threads
You may not post replies
Eklenti Ekleyemezsiniz
You may not edit your posts

BB code is Açık
Smileler Açık
[IMG] Kodları Açık
HTML-KodlarıKapalı
Trackbacks are Açık
Pingbacks are Açık
Refbacks are Açık
Gitmek istediğiniz klasörü seçiniz

Benzer Konular
Konu Konuyu Başlatan UslanmaM Cevaplar Son Mesaj
Pink-Stupid Girls yON3t1C1 En Çok İzlenen YouTube Videoları 0 06-05-2007 10:49 PM
Titans have big holes to fill at draft (AP) USLANMAM Sport News 0 04-24-2007 05:50 AM
Titans have big holes to fill at draft (AP) USLANMAM Sport News 0 04-23-2007 10:50 PM
Cisco fixes wireless security holes USLANMAM Technology News 0 04-13-2007 02:40 AM
Madonna - I'm So Stupid ABYSS Yabancı Şarkı Sözleri 0 11-24-2006 04:00 AM


Bütün Zaman Ayarları WEZ +2 olarak düzenlenmiştir. Şu Anki Saat: 02:42 AM .
Üyelerimiz görüşlerini önceden onay olmadan anında yazabilmektedir, bu yazılardan dolayı doğabilecek her türlü sorumluluk yazan kullanıcılara aittir, UslanmaM yoneticileri itina ile icerik kontrolleri yapmaktadir, yine de UslanmaM' da yasalara aykırı unsurlar bulursanız İLETİŞİME veya 0555 582 46 56 numaralı telefona bildirebilirsiniz, gereği yapılacaktır.
English Explanation: Our users can give their opinions without getting any approval in our site, all the responsibilities which can rise from these articles belong to these users, the managers of UslanmaM control the contents very carrefully, but if you find any item opposite to the rules CONTACT or dial +90555 582 46 56


Powered by vBulletin Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.'e Aittir.
Tercüme Eden : TEKplatform
Search Engine Optimization by vBSEO 3.2.0
[Gizlilik Bildirimi]-[UslanmaM Kuralları]-[UslanmaM İletişim/Contact]
Alexa
Sagopa Kajmer*bebek *izafet*Web Hattı*kadınlar*MaxiCep*araba