Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Breakable
Kevin Poulsen, SecurityFocus 2002-01-16

A U.K. security expert is preparing to unveil a trove of serious vulnerabilities in Oracle's database products. Can the company redefine 'unbreakable' in time?

Comments Mode:
14 evaluations missed what 1 guy found... 2002-01-16
Anonymous (5 replies)
14 evaluations missed what 1 guy found... 2002-01-17
Brad C. Johnson, Vice President, SystemExperts Corp.
I think it's right to question what these 14 evaluations did, and why they missed these problems. I think it's wrong to assume these evaluations were useless and the people who did them aren't providing value.

The reality is, Litchfield is an expert who had incentives to try and find problems: he is writing a tool that's supposed to evaluate (scan) Oracle. If you run Nessus against your site and it shows no problems, does that mean you're completely safe? No. If you have other problems, which assuredly you do, does that also imply Nessus (or Nsat or Ncat or eEye or whatever) is useless? No.

The more realistic problem is that these 14 evaluations were all too similar. So running more of the same is likely to generate results that are more of the same. If you're really trying to find problems, then you need to increase the probability that new tools (evaluations) are looking for different things so the space of things you're considering and testing is more/wider.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/309/9947#9947
Not just some guy 2002-01-17
BLKMGK
PGU 2002-01-16
Anonymous (1 replies)
PGU 2002-01-17
Anonymous
Breakable 2002-01-17
Anonymous (2 replies)
Breakable 2002-01-17
KZ
Breakable 2002-01-17
Anonymous
Schneier is right 2002-01-17
Anonymous (1 replies)
Schneier is right 2002-01-17
Brad C. Johnson, Vice President, SystemExperts Corp.
Breakable 2002-01-17
drama at slakin d0t n3t (1 replies)
Breakable 2002-01-17
Anonymous
What Oracle means by UnBreakable 2002-01-17
Anonymous (3 replies)
UnBreakable <- Can't break in? 2002-01-18
Anonymous
What Oracle means by UnBreakable 2002-01-18
Anonymous
enron 2002-01-17
kkr
Breakable 2002-01-17
Grizzly
Breakable 2002-01-17
Anonymous
Breakable 2002-01-17
Anonymous (1 replies)
Breakable 2002-01-18
Anonymous
Oracle9i = 0 Evaluations 2002-01-17
Ross
Breakable 2002-01-18
An ex-Oracle security guy (1 replies)
Breakable 2002-01-18
Anonymous
Breakable 2002-01-18
Anonymous
Breakable 2002-01-18
An Interested Party
Playing with words 2002-01-20
Tired guy







 

Privacy Statement
Copyright 2008, SecurityFocus