Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> RE: 65 Oracle security papers, articles and presentations

RE: 65 Oracle security papers, articles and presentations

From: Boris Dali <boris_dali_at_yahoo.ca>
Date: Tue, 08 Apr 2003 13:24:00 -0800
Message-ID: <F001.0057D5E8.20030408132400@fatcity.com>


What I meant by "cure" is the way to obtain (not to prevent from obtaining) these passwords from the library cache (or any other) dumps.

It works like a charm (meaning it is still a security hole of a kind) in my 8.1.7.4.0, but it doesn't show clear text passwords in 9.2.0.3.0 any more (meaning it seems to be fixed). The question was if malicious user can still get it somehow in 9i in a similar fashion


Post your free ad now! http://personals.yahoo.ca
-- 
Please see the official ORACLE-L FAQ: http://www.orafaq.net
-- 
Author: Boris Dali
  INET: boris_dali_at_yahoo.ca

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message
to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from).  You may
also send the HELP command for other information (like subscribing).
Received on Tue Apr 08 2003 - 16:24:00 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US