Call: +44 (0)1904 557620 Call

Pete Finnigan's Oracle Security Weblog

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

[Previous entry: "Oracle Password Repository"] [Next entry: "SQL Injection video"]

How to bypass the protection implemented by DBMS_ASSERT

Alex has today released a paper on how to bypass the fix that Oracle has created for a lot of SQL Injection vulnerabilities fixed in recent CPU's. Oracle has used a package DBMS_ASSERT to stop SQL Injection. Alex has detailed in his paper "Bypassing Oracle DBMS_ASSERT" how to bypass this package and make a good proportion of the bugs fixed in previous CPU's exploitable again.

The interesting point in the paper is that Oracle didnt have an issue with Alex publishing this paper and revealing the issues. Why?