what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 47 of 47 RSS Feed

Files from Alexander Kornbrust

Email addressak at red-database-security.com
First Active2005-07-14
Last Active2009-04-16
oracle_reports_read_any_xml_file.txt
Posted Jan 25, 2006
Authored by Alexander Kornbrust | Site red-database-security.com

The Oracle Reports parameter customize can read any file by using an absolute or relative file name. Parts of the file content are displayed in the Reports error message

tags | advisory
SHA-256 | f0314d4bf413e9fae79071434d7822edcb24e11ed4940e67ecba30ac5acd510f
oracle_tde_unencrypted_sga.txt
Posted Jan 25, 2006
Authored by Alexander Kornbrust | Site red-database-security.com

The Oracle security feature "Transparent Data Encryption" is storing the masterkey unencrypted in the SGA. A skilled attacker or non-security DBA can retrieve the plaintext masterkey.

tags | advisory
SHA-256 | 53734153442fd7cb77962aa30534146324550a2e0a0680fe77b1bc8e91a0d592
oracle-wf_monitor.txt
Posted Oct 26, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

Oracle Workflow is part of the database or application server installation. The parameter response form is vulnerable against XSS/CSS attacks.

tags | advisory
SHA-256 | 2eb6c4ef458b17429b16b1a95e05c214585b85fc4637ec1a482c95d69ecf2c6f
oracle_forms_shutdown.txt
Posted Oct 8, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

The Oracle Forms servlet can be used to cause a denial of service against the TNS Listener.

tags | advisory, denial of service
SHA-256 | 72d657c9d34a08163e0ac91b91a9aecbea265ce6791086334997b32c828e111f
oracle_isqlplus_shutdown.txt
Posted Oct 8, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

The web interface for iSQLPlus in Oracle Database 9.0.2.4 can be used to cause a denial of service against the TNS Listener.

tags | advisory, web, denial of service
SHA-256 | ab783831ce9a6285a953756ea16236eef2b4d64b31bed4e8bbd16eb3b6fcc156
oracle_xmldb_css.txt
Posted Oct 8, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

The XMLDB in Oracle Database 9i Release 2 is susceptible to cross site scripting attacks.

tags | exploit, xss
SHA-256 | f60d5590bc2279e0eb2f276fa15e511bb23e3ee2dfdb2f652d24eead062a25fd
oracle_isqlplus_css.txt
Posted Oct 8, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

Oracle Database 9.0.2.4 with iSQLPlus is susceptible to a cross site scripting flaw.

tags | exploit, xss
SHA-256 | 4e46dcca1545f3b988b96e9d9519b788e4170a780349fceb576370c8407df3be
oracle_htmldb_plaintext_password.txt
Posted Oct 8, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

During the manual installation process of Oracle HTMLDB, the SYS password is logged in plaintext into the file install.lst.

tags | advisory
SHA-256 | 8aade996b0fb6512d99be5ac7c4565565139723d4135a6aaeb91226a61a3af85
oracle_htmldb_css.txt
Posted Oct 8, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

The Oracle HTMLDB contains some cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | d2f371949cb27d269d5b9249b1197ca0e6160b0e34383d38e2056e71438de8db
sql_injection_reports_us.txt
Posted Sep 15, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

Oracle Reports fails to properly sanitize user input allowing for SQL injection attacks.

tags | advisory, sql injection
SHA-256 | 1231437f23fca1da680f92cd8c0d24b09e7b06a69abcf763b7b9272ddd7ced0a
oracle_checkpwd.zip
Posted Aug 24, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

A dictionary based Oracle password checker. This is a useful and fast (150.000 pw/sec) tool for DBAs to identify Oracle accounts with weak or default passwords.

tags | cracker
SHA-256 | 347557ee38aed91ccdfda881256b418152b5fc74c3ede2186cf61ff83fe5f29c
oracleDBMS.txt
Posted Aug 6, 2005
Authored by Alexander Kornbrust

Every user with CREATE JOB privilege can switch the SESSION_USER to SYS by executing a database job via dbms_scheduler on Oracle 10g.

tags | advisory
SHA-256 | 89a141519dcef0c60eb5caae4118b9350bed9c359a49fba7854f155c388e595c
oracleDisable.txt
Posted Aug 6, 2005
Authored by Alexander Kornbrust

Fine grained audit (FGA) is disabled for all users if the user SYS runs a SELECT statement on a FGA object in Oracle 9i / 10g.

tags | advisory
SHA-256 | ef0e69af9d00f437ba72ca0fee630f111a4921211bcba924fef4da010fb8148c
AKSEC2003-007.txt
Posted Jul 20, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

Oracle Reports allows for the reading of parts of XML files via a customized parameter.

tags | advisory
SHA-256 | 4d27059175e1dcc7aeac399414cc2c7127df1d03ac5be93c671f03ad7943b4db
AKSEC2003-013.txt
Posted Jul 20, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

Oracle (Web) Forms versions 4.5, 5.0, 6.0, 6i, 9i, and 10g allow for remote command execution.

tags | advisory, remote, web
SHA-256 | 03f7b32a794cc3457f7a79373ed1363ef640d03456f77d185a3b500f8658e02e
AKSEC2003-014.txt
Posted Jul 20, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

Oracle Reports versions 6.0, 6i, 9i, and 10g allows for unauthorized command execution.

tags | advisory
SHA-256 | c4d8f576853527f5797d50ebac8b56c69d36581500b4309070c285b0057679f2
AKSEC2003-005.txt
Posted Jul 20, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

Oracle Reports versions 6.0, 6i, 9i, and 10g allow for arbitrary file overwrites.

tags | advisory, arbitrary
SHA-256 | 601395cdc955fabeda3c3d734002f48426a76e9cd93e33bd11a599d3182ac047
oracleSilent.txt
Posted Jul 15, 2005
Authored by Alexander Kornbrust | Site red-database-security.com

It appears that Oracle may have silently fixed additional bugs in their recent security bugfix release.

tags | advisory
SHA-256 | e0092d5f6bdb2133ade57acba8c98c3d9e47d8cb0d9564b550ca52fec6509e26
AKSEC2003-006-4.txt
Posted Jul 14, 2005
Authored by Alexander Kornbrust

Red-Database-Security GmbH Advisory - Oracle Forms 4.5, 6.0, 6i, and 9i suffer from an insecure file handling vulnerability.

tags | advisory
SHA-256 | fa4eaf8e7d0fdc3d758812044a9f5867ff11c7040921a31aa5d1a5658f5ca1ef
AKSEC2003-006-3.txt
Posted Jul 14, 2005
Authored by Alexander Kornbrust

Red-Database-Security GmbH Advisory - Oracle Formsbuilder version 9.0.4 fails to remove files from a temporary directory after closing. These files hold passwords.

tags | advisory
SHA-256 | 92d250e9df585c90c8a7056d41f17421ea64bf7a057934e647141c68176c2a7b
AKSEC2003-006-2.txt
Posted Jul 14, 2005
Authored by Alexander Kornbrust

Red-Database-Security GmbH Advisory - Oracle JDeveloper versions 9.0.4, 9.0.5, and 10.1.2 suffer from a security issue where they store passwords in the clear.

tags | advisory
SHA-256 | 1ef7d326099db85757b1d0d45d41e4e79836e1fb7b8ff8e4749aba6ac6cae850
AKSEC2003-006-1.txt
Posted Jul 14, 2005
Authored by Alexander Kornbrust

Red-Database-Security GmbH Advisory - Oracle JDeveloper versions 9.0.4, 9.0.5, and 10.1.2 suffer from a security issue where they pass a plaintext password to sqlplus.

tags | advisory
SHA-256 | 6cc2a4972fdac4f610e2d1dd525a1fede3e1ecfc4372f8b465e4547f449f5fa4
Page 2 of 2
Back12Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close