Amazines Free Article Archive
www.amazines.com - Thursday, April 25, 2024
Read about the most recent changes and happenings at Amazines.com
Log into your account or register as a new author. Start submitting your articles right now!
Search our database for articles.
Subscribe to receive articles emailed straight to your email account. You may choose multiple categories.
View our newest articles submitted by our authors.
View our most top rated articles rated by our visitors.
* Please note that this is NOT the ARTICLE manager
Add a new EZINE, or manage your EZINE submission.
Add fresh, free web content to your site such as newest articles, web tools, and quotes with a single piece of code!
Home What's New? Submit/Manage Articles Latest Posts Top Rated Article Search
Google
Subscriptions Manage Ezines
CATEGORIES
 Article Archive
 Advertising (133573)
 Advice (161671)
 Affiliate Programs (34799)
 Art and Culture (73855)
 Automotive (145712)
 Blogs (75614)
 Boating (9851)
 Books (17223)
 Buddhism (4130)
 Business (1330640)
 Business News (426446)
 Business Opportunities (366518)
 Camping (10973)
 Career (72795)
 Christianity (15848)
 Collecting (11638)
 Communication (115089)
 Computers (241953)
 Construction (38962)
 Consumer (49953)
 Cooking (17080)
 Copywriting (6733)
 Crafts (18203)
 Cuisine (7549)
 Current Affairs (20319)
 Dating (45908)
 EBooks (19703)
 E-Commerce (48258)
 Education (185521)
 Electronics (83524)
 Email (6438)
 Entertainment (159855)
 Environment (28973)
 Ezine (3040)
 Ezine Publishing (5453)
 Ezine Sites (1551)
 Family & Parenting (111007)
 Fashion & Cosmetics (196605)
 Female Entrepreneurs (11853)
 Feng Shui (134)
 Finance & Investment (310615)
 Fitness (106469)
 Food & Beverages (63045)
 Free Web Resources (7941)
 Gambling (30227)
 Gardening (25202)
 Government (10519)
 Health (630137)
 Hinduism (2206)
 Hobbies (44083)
 Home Business (91657)
 Home Improvement (251211)
 Home Repair (46244)
 Humor (4723)
 Import - Export (5459)
 Insurance (45104)
 Interior Design (29616)
 International Property (3488)
 Internet (191031)
 Internet Marketing (146687)
 Investment (22861)
 Islam (1161)
 Judaism (1352)
 Law (80507)
 Link Popularity (4596)
 Manufacturing (20914)
 Marketing (99316)
 MLM (14140)
 Motivation (18233)
 Music (27000)
 New to the Internet (9496)
 Non-Profit Organizations (4048)
 Online Shopping (129734)
 Organizing (7813)
 Party Ideas (11855)
 Pets (38165)
 Poetry (2229)
 Press Release (12689)
 Public Speaking (5643)
 Publishing (7566)
 Quotes (2407)
 Real Estate (126700)
 Recreation & Leisure (95495)
 Relationships (87674)
 Research (16182)
 Sales (80350)
 Science & Technology (110291)
 Search Engines (23514)
 Self Improvement (153300)
 Seniors (6220)
 Sexuality (36010)
 Small Business (49312)
 Software (83034)
 Spiritual (23517)
 Sports (116155)
 Tax (7663)
 Telecommuting (34070)
 Travel & Tourism (308305)
 UK Property Investment (3123)
 Video Games (13382)
 Web Traffic (11790)
 Website Design (56919)
 Website Promotion (36663)
 World News (1000+)
 Writing (35843)
Author Spotlight
DESIGNPLUZ DIGITALAGENCY

Designpluz has steadily matured from a passionate graphics design start-up, into a full service digi...more
ELLIOT CHANG

Financial analyst and author writing on economy and business. ...more
TAL BARNEA

Tal is an electrical engineer with over 25 years of expertise with hardware, software, mechanical an...more
MANMOHAN SINGH

Digital marketing professional with 8 years of experience. A good listner, Stratgist and fun loving ...more
LEMUEL ASIBAL

Lemuel Asibal is a web content writer who also ventures on writing articles and blog posts about any...more


Researcher misinterprets oracle advisory, discloses unpatcheddatabase vulnerability by icdenta icdenta





Article Author Biography
Researcher misinterprets oracle advisory, discloses unpatcheddatabase vulnerability by
Article Posted: 06/24/2012
Article Views: 65
Articles Written: 1096
Word Count: 487
Article Votes: 0
AddThis Social Bookmark Button

Researcher misinterprets oracle advisory, discloses unpatcheddatabase vulnerability


 
Business,Business News,Business Opportunities
Instructions on how to exploit an unpatched Oracle Database Servervulnerability in order to intercept the information exchangedbetween clients and databases were published by a securityresearcher who erroneously thought that the company had patched theflaw. Oracle's April 2012 Critical Patch Update (CPU) advisory , published on April 17, credited security researcher Joxean Koretfor a vulnerability he reported through cyber intelligence firmiSight Partners. [ In a major finding, InfoWorld uncovered a fundamental Oracle flaw and its repercussions for database customers.

Learn how tosecure your systems with Roger Grimes' Security Adviser blog and Security Central newsletter , both from InfoWorld.

Subscribe to the InfoWorld Daily newsletter to make sure you don't miss an article. ] In an email sent to the Full Disclosure mailing list on April 18, Koretrevealed that the vulnerability is located in the Oracle TNSListener, a component that routes connections from clients toOracle database servers depending on which database they are tryingto reach. TNS Listener has a default feature, introduced in 1999, that allowsclients to register a database service or database instanceremotely without authentication, Koret said. The client sends a remote registration request to the TNS Listenerand defines a new service name, its IP address, the databaseinstances under it, and other settings. The TNS Listener thenstarts routing all client requests that include that service nameor database instance.

However, TNS Listener also allows the remote registration of adatabase instance or service name that is already registered, Koretsaid. "The TNS listener will consider this newer registeredinstance name a cluster instance (Oracle RAC, Real ApplicationClusters) or a fail over instance (Oracle Fail over)," he said. In this case, the TNS Listener performs load balancing between thetwo instances by sending the first client to the most recentlyregistered one and the second client to the original one. Thisallows a local attacker to route between 50 and 75 percent ofclients to a database server that he controls, Koret said. The attacker can then use the TNS Listener on the server hecontrols to route the client requests back to the legitimatedatabase instance, effectively establishing a TNS proxy that allowshim to intercept all data exchanged between clients and thetargeted database.

However, this is not the only attack scenario that thisvulnerability allows. By being in a man-in-the-middle situation,the attacker can also inject rogue commands in the SQL queries sentby clients or completely hijack their sessions to execute arbitraryqueries, Koret said. The researcher mentioned that he didn't test whether Oracle's patchfor this vulnerability, that he believed to be included in theApril 2012 CPU, actually addressed all attack vectors. However, after a few follow-up emails with Oracle, he realized thatthe company hadn't actually patched the flaw for currentlysupported versions of the database server, but instead addressed itin an yet-to-be-released version.

I am an expert from vinyl-cutterplotter.com, while we provides the quality product, such as Simple Graph Plotter , Contour Cutting Plotter, Cutting Plotter Machine,and more.

Related Articles - Simple Graph Plotter, Contour Cutting Plotter,

Email this Article to a Friend!

Receive Articles like this one direct to your email box!
Subscribe for free today!

 Rate This Article  
Completely useless, should be removed from directory.
Minimal useful information.
Decent and informative.
Great article, very informative and helpful.
A 'Must Read'.

 

Do you Agree or Disagree? Have a Comment? POST IT!

 Reader Opinions 
Submit your comments and they will be posted here.
Make this comment or to the Author only:
Name:
Email:
*Your email will NOT be posted. This is for administrative purposes only.
Comments: *Your Comments WILL be posted to the AUTHOR ONLY if you select PRIVATE and to this PUBLIC PAGE if you select PUBLIC, so write accordingly.
 
Please enter the code in the image:



 Author Login 
LOGIN
Register for Author Account

 

Advertiser Login

 

ADVERTISE HERE NOW!
   Limited Time $60 Offer!
   90  Days-1.5 Million Views  

 

Great Paranormal Romance


TIM FAY

After 60-plus years of living, I am just trying to pass down some of the information that I have lea...more
LAURA JEEVES

At LeadGenerators, we specialise in content-led Online Marketing Strategies for our clients in the t...more
ALEX BELSEY

I am the editor of QUAY Magazine, a B2B publication based in the South West of the UK. I am also the...more
GENE MYERS

Author of four books and two screenplays; frequent magazine contributor. I have four other books "in...more
SUSAN FRIESEN

Located in the lower mainland of B.C., Susan Friesen is a visionary brand strategist, entrepreneur, ...more
STEVERT MCKENZIE

Stevert Mckenzie, Travel Enthusiast. ...more
STEPHEN BYE

Steve Bye is currently a fiction writer, who published his first novel, ‘Looking Forward Through the...more
SHALINI MITTAL

A postgraduate in Fashion Technology. Shalini is a writer at heart! Writing for her is an expression...more
ADRIAN JOELE

I have been involved in nutrition and weight management for over 12 years and I like to share my kn...more
JAMES KENNY

James is a Research Enthusiast that focuses on the understanding of how things work and can be impro...more

HomeLinksAbout UsContact UsTerms of UsePrivacy PolicyFAQResources
Copyright © 2024, All rights reserved.
Some pages may contain portions of text relating to certain topics obtained from wikipedia.org under the GNU FDL license