<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Musings on Database Security &#187; DBA</title>
	<atom:link href="http://www.slaviks-blog.com/category/dba/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.slaviks-blog.com</link>
	<description>Slavik&#039;s Blog</description>
	<lastBuildDate>Wed, 07 Dec 2011 17:07:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>YAOPC &#8211; Yet Another Oracle Password Cracker</title>
		<link>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/</link>
		<comments>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/#comments</comments>
		<pubDate>Fri, 28 Jan 2011 03:07:51 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[DBA]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Python]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=292</guid>
		<description><![CDATA[I was preparing a presentation for RMOUG and wanted to show how easy it is to crack Oracle passwords once you get the hashes. There are a lot of Oracle password crackers out there but I find that using low level C code in a presentation makes the audience leave before you get to the half [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Side-Channel Information Leakage using VPD</title>
		<link>http://www.slaviks-blog.com/2009/08/18/side-channel-information-leakage-using-vpd/</link>
		<comments>http://www.slaviks-blog.com/2009/08/18/side-channel-information-leakage-using-vpd/#comments</comments>
		<pubDate>Tue, 18 Aug 2009 23:44:36 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[DBA]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=156</guid>
		<description><![CDATA[A guest post by Roy Fox, Sentrigo’s Head of Security Research. Thanks Roy! Introduction Black boxes are rarely entirely black. Many have side effects in addition to their functional effects, and virtually all consume external resources of one kind or another. When these effects or consumption are detectable, and when they reveal information on the [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2009/08/18/side-channel-information-leakage-using-vpd/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Oracle Jul2009 CPU</title>
		<link>http://www.slaviks-blog.com/2009/07/14/oracle-jul2009-cpu/</link>
		<comments>http://www.slaviks-blog.com/2009/07/14/oracle-jul2009-cpu/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 22:49:35 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[DBA]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[cpus]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=142</guid>
		<description><![CDATA[Wow, that&#8217;s a big one! Not so much as in the number of security bugs fixed but from the severity point of view. Oracle fixed 30 vulnerabilities which is a bit less than the previous CPUs. Most of the problems are in the core database product and centered around the network components. The advanced queueing [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2009/07/14/oracle-jul2009-cpu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sentrigo integrates with Repscan to provide vulnerability assessment</title>
		<link>http://www.slaviks-blog.com/2009/04/16/sentrigo-integrates-with-repscan-to-provide-vulnerability-assessment/</link>
		<comments>http://www.slaviks-blog.com/2009/04/16/sentrigo-integrates-with-repscan-to-provide-vulnerability-assessment/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 21:23:09 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[DBA]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sentrigo]]></category>
		<category><![CDATA[database security]]></category>
		<category><![CDATA[repscan]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=124</guid>
		<description><![CDATA[Anybody using Oracle databases, and anyone who is concerned about vulnerability assessment should be familiar with Repscan &#8211; the best scanner for Oracle databases, developed by Alexander Kornbrust’s Red-Database-Security. The scanner, built upon Alex&#8217;s extensive experience in doing thousands of pen tests and database reviews, has some very unique features and tests. At Sentrigo, I [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2009/04/16/sentrigo-integrates-with-repscan-to-provide-vulnerability-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting issue with arguments for MDSYS.SDO_JOIN</title>
		<link>http://www.slaviks-blog.com/2009/01/30/interesting-issue-with-arguments-for-mdsyssdo_join/</link>
		<comments>http://www.slaviks-blog.com/2009/01/30/interesting-issue-with-arguments-for-mdsyssdo_join/#comments</comments>
		<pubDate>Sat, 31 Jan 2009 01:16:32 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[DBA]]></category>
		<category><![CDATA[Fuzzor]]></category>
		<category><![CDATA[Oracle]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=107</guid>
		<description><![CDATA[I was playing a bit with FuzzOr and trying out different Oracle built-in schemas on 11g when I stumbled across something interesting in the parameters for MDSYS.SDO_JOIN. This caused FuzzOr to fail in fuzzing the function so I took a closer look. SYS&#62; select argument_name, type_owner, type_name, position, sequence from all_arguments where object_name = &#8216;SDO_JOIN&#8217;; [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2009/01/30/interesting-issue-with-arguments-for-mdsyssdo_join/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Oracle CPU Dissected</title>
		<link>http://www.slaviks-blog.com/2009/01/20/oracle-cpu-dissected/</link>
		<comments>http://www.slaviks-blog.com/2009/01/20/oracle-cpu-dissected/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 06:27:47 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[DBA]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[technical tips]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=97</guid>
		<description><![CDATA[In light of last week&#8217;s CPU announcements, I invited my colleague Aviv Pode, Sentrigo&#8217;s Head of Security Research, to submit a special guest blog post. Thanks Aviv! Oracle releases Critical Patch Updates (CPUs) every three months, containing security code fixes to vulnerabilities discovered by its security personnel or external researchers and hackers. By exploring these [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2009/01/20/oracle-cpu-dissected/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.631 seconds -->

