On TechRepublic: 12 tech terms that make you sound old
BNET Business Network:
BNET
TechRepublic
ZDNet

February 26th, 2007

Researcher issues Oracle DB 'cursor injection' warning

Posted by Ryan Naraine @ 11:42 am

Categories: Black Hat, Data theft, Exploit code, Hackers, Oracle, Pen testing, Responsible disclosure, Vulnerability research, Zero-day attacks

Tags: Database, Oracle Corp., Attacker, Vulnerability, PL/SQL, Ryan Naraine

In Focus » See more posts on: Black Hat, Oracle

David Litchfield's ongoing assault on Oracle databases has unearthed a new method of exploiting PL/SQL injection vulnerabilities.

Litchfield, co-founder and managing director at NGSS (Next Generation Security Software), plans to discuss the new technique at the Black Hat DC 2007 conference later this week.

In a paper (PDF) released ahead of the show, LItchfield warned that the new attack method entirely removes the requirement for an attacker to create functions to be able to execute arbitrary SQL. "This should finally put to bed those arguments about whether such and such a PL/SQL injection flaw is exploitable in practice or not by a user with only the CREATE SESSION system privilege," he explained.

The technique, called "cursor injection," is a direct challenge to Oracle's assertion that an attacker needs the ability to create a procedure or function on a vulnerable database. Instead, Litchfield argues, an attacker can inject a pre-compiled cursor into vulnerable PL/SQL objects.

His position is that *all* SQL injection flaws can be fully exploited without any system privilege other than CREATE SESSION and DBAs should be wary of a vendor attempting to downplay the severity of certain vulnerabilities.

Litchfield, who found himself embroiled in a flaw disclosure dispute with Oracle at last year's conference, recently issued an alert for a brand-new class of vulnerabilities affecting Oracle databases. In that research report, he warned that dangling cursors in database code can be manipulated and used to expose sensitive data.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
Hear hear
And... the SQL Server drivers are far more robust than the Oracle ones.

Oracle keep on breaking their OLE/DB drivers and then fixing them again.... (Read the rest)
Posted by: Jeremy.Lloyd Posted on: 02/27/07 You are currently: a Guest | | Terms of Use
Unbreakable.... ??  redtrain65 | 02/26/07
Hear hear  Jeremy.Lloyd | 02/27/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here