<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Musings on Database Security &#187; Oracle</title>
	<atom:link href="http://www.slaviks-blog.com/category/oracle/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.slaviks-blog.com</link>
	<description>Slavik&#039;s Blog</description>
	<lastBuildDate>Wed, 07 Dec 2011 17:07:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hacking exposed presentation and source code</title>
		<link>http://www.slaviks-blog.com/2011/05/04/hacking-exposed-presentation-and-source-code/</link>
		<comments>http://www.slaviks-blog.com/2011/05/04/hacking-exposed-presentation-and-source-code/#comments</comments>
		<pubDate>Wed, 04 May 2011 22:17:28 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=313</guid>
		<description><![CDATA[Here is the presentation and demo application I&#8217;ve used for the hacking exposed webinar I did on April 14th. The download file includes an eclipse project and instructions under the &#8220;etc&#8221; folder. It also includes a few scripts I used for blind SQL injection and worm infection. Tell me what you think&#8230; HackingExposed]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/05/04/hacking-exposed-presentation-and-source-code/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>YAOPC &#8211; Yet Another Oracle Password Cracker</title>
		<link>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/</link>
		<comments>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/#comments</comments>
		<pubDate>Fri, 28 Jan 2011 03:07:51 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[DBA]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Python]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=292</guid>
		<description><![CDATA[I was preparing a presentation for RMOUG and wanted to show how easy it is to crack Oracle passwords once you get the hashes. There are a lot of Oracle password crackers out there but I find that using low level C code in a presentation makes the audience leave before you get to the half [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>UKOUG registration errors</title>
		<link>http://www.slaviks-blog.com/2010/11/18/ukoug-registration-errors/</link>
		<comments>http://www.slaviks-blog.com/2010/11/18/ukoug-registration-errors/#comments</comments>
		<pubDate>Fri, 19 Nov 2010 07:59:32 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[technical tips]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=286</guid>
		<description><![CDATA[I&#8217;m flying to UK on the 28th to participate in the UK Oracle user group conference. It&#8217;s one of the more technical and interesting conferences out there for Oracle and I love attending. So, as a speaker, I had to register. While in the process of submitting my details, I got an error from the [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/11/18/ukoug-registration-errors/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Mixed case passwords for Oracle</title>
		<link>http://www.slaviks-blog.com/2010/09/01/mixed-case-passwords-for-oracle/</link>
		<comments>http://www.slaviks-blog.com/2010/09/01/mixed-case-passwords-for-oracle/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 00:03:08 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=272</guid>
		<description><![CDATA[So, we all know that Oracle used to be non-case sensitive when it came to user names and passwords. We also know that since 11g this is not the case and Oracle, by default, is case sensitive. The one thing I wanted to point out is that even if you are using sec_case_sensitive_logon=false and ignore [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/09/01/mixed-case-passwords-for-oracle/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>dbms_jvm_exp_perms 0day fixed on Windows 11gR2</title>
		<link>http://www.slaviks-blog.com/2010/04/08/dbms_jvm_exp_perms-0day-fixed-on-windows-11gr2/</link>
		<comments>http://www.slaviks-blog.com/2010/04/08/dbms_jvm_exp_perms-0day-fixed-on-windows-11gr2/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 17:48:22 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[technical tips]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=262</guid>
		<description><![CDATA[Alex wrote a nice blog post showing that the 0day found by David Litchfield [pdf] is now fixed in the newest Oracle 11.2.0.1 release for Windows. He has some analysis of the fix as well as some good examples of using Repscan to view permissions and audit records using the online browser. Whenever I need [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/04/08/dbms_jvm_exp_perms-0day-fixed-on-windows-11gr2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>pysql</title>
		<link>http://www.slaviks-blog.com/2010/04/06/pysql/</link>
		<comments>http://www.slaviks-blog.com/2010/04/06/pysql/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 00:36:15 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[SQL*Plus]]></category>
		<category><![CDATA[technical tips]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=259</guid>
		<description><![CDATA[During the weekend, I stumbled across an interesting project named pysql. The project aims to replace SQL*Plus with a sane shell written in Python with history, tab completion and many extensions. Being a veteran of using SQL*Plus, I know that some of the above can be actually achieved on Linux/Unix environments with SQL*Plus using a [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/04/06/pysql/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.238 seconds -->

