This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
OWASP AppSec DC 2012/New and Improved Hacking Oracle from Web
From OWASP
Revision as of 20:42, 2 March 2012 by Mark.bristow (talk | contribs) (Created page with "<noinclude>{{:OWASP AppSec DC 2012 Header}}</noinclude> __NOTOC__ == The Presentation == rightThere are a number of attacks against Oracle dat...")
Registration Now OPEN! | Hotel | Schedule | Convention Center | AppSecDC.org
The Presentation
There are a number of attacks against Oracle database and in almost every other CPU there is a shiny new exploit which allows a malicious database user to gain DBA privileges on the back-end database. Exploiting things over web apps via a SQL Injection vulnerability, is not quite the same due to restrictions posed by the database. In 2010, I showed a few attack vectors which can be used, depending upon what privileges the database user has, to carry out advanced exploitation. Examples of advanced exploitation include privilege escalation attacks and OS code execution against back-end database. This talk will show new attack vectors which will allow an attacker to carry out any old/new exploit against oracle database via web apps. Unlike previous attack vectors these don't require any special privileges and exist from Oracle 9i to 11g R2.The Speakers
Sumit Siddharth
Gold Sponsors |
||||
Silver Sponsors |
||||
Small Business |
||||
Exhibitors |