<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Three Tier Oracle Security in London ~ Paul M. Wright</title>
	<atom:link href="http://www.oracleforensics.com/wordpress/index.php/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.oracleforensics.com/wordpress</link>
	<description>ORACLE SECURITY AND COMPUTER FORENSICS</description>
	<lastBuildDate>Wed, 10 Mar 2010 00:11:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>sec_return_server_release_banner Secure by Default?</title>
		<link>http://www.oracleforensics.com/wordpress/index.php/2010/03/08/sec_return_server_release_banner-secure-by-default/</link>
		<comments>http://www.oracleforensics.com/wordpress/index.php/2010/03/08/sec_return_server_release_banner-secure-by-default/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 00:11:43 +0000</pubDate>
		<dc:creator>Paul Wright</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.oracleforensics.com/wordpress/?p=503</guid>
		<description><![CDATA[Hello World,
Congratulations to Sentrigo for being nominated again in the SC Awards in the US for Hedgehog.
http://www.scmagazineus.com/scawards2010-finalists/section/1309/
Just came across an ex-colleague from Pentest Ltd named Simon Fletcher who has started a blog on Oracle Security.
http://blog.fifteentwentyone.co.uk/2010/02/sql92security.html
Nice post and good luck with the new blog. Oracle config issues like these are interesting for already very highly secured [...]]]></description>
		<wfw:commentRss>http://www.oracleforensics.com/wordpress/index.php/2010/03/08/sec_return_server_release_banner-secure-by-default/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-Business Suite Security and DBMS_LDAP.INIT</title>
		<link>http://www.oracleforensics.com/wordpress/index.php/2010/03/01/e-business-suite-security-and-dbms_ldap-init/</link>
		<comments>http://www.oracleforensics.com/wordpress/index.php/2010/03/01/e-business-suite-security-and-dbms_ldap-init/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 01:23:22 +0000</pubDate>
		<dc:creator>Paul Wright</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.oracleforensics.com/wordpress/?p=471</guid>
		<description><![CDATA[Hi Folks,
Vulnerability in E-Business Suite R12 requires non-default diagnostics mode so Low risk.
http://www.securityfocus.com/archive/1/509460
Having said that it is worth keeping an eye on Internet facing Oracle applications, though there is not a huge amount on this from O&#8217;Reilly and Apress.
Google books has a relevant book free of charge named &#8220;Security, Audit and Control Features Oracle E-Business [...]]]></description>
		<wfw:commentRss>http://www.oracleforensics.com/wordpress/index.php/2010/03/01/e-business-suite-security-and-dbms_ldap-init/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing Java in Oracle Update and escalating to SYSDBA</title>
		<link>http://www.oracleforensics.com/wordpress/index.php/2010/02/25/securing-java-in-oracle-update-and-escalating-to-sysdba/</link>
		<comments>http://www.oracleforensics.com/wordpress/index.php/2010/02/25/securing-java-in-oracle-update-and-escalating-to-sysdba/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 03:24:05 +0000</pubDate>
		<dc:creator>Paul Wright</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.oracleforensics.com/wordpress/?p=437</guid>
		<description><![CDATA[Updated Securing Java in Oracle paper  here. 
David&#8217;s work  has drawn attention.
http://www.h-online.com/security/news/item/Vulnerability-in-Oracle-11gR2-allows-system-privileges-for-all-Update-923143.html
http://www.computerworld.com/s/article/9151318/Black_Hat_Zero_day_hack_of_Oracle_11g_database_revealed?taxonomyId=1
etc..
What the reports miss is that this definitely affects 10.2.0.4.3 as well in a big way.
Oracle have provided some guidance in the absence of a patch:
- revoke execute on "oracle/aurora/util/Wrapper" from public;
- grant execute on sys.dbms_jvm_exp_perms to IMP_FULL_DATABASE;
- grant execute on sys.dbms_jvm_exp_perms [...]]]></description>
		<wfw:commentRss>http://www.oracleforensics.com/wordpress/index.php/2010/02/25/securing-java-in-oracle-update-and-escalating-to-sysdba/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
