RE: oracle VA/PT

From: Gus Fritschie (gfritschie_at_hotmail.com)
Date: 09/28/05

  • Next message: dave kleiman: "RE: Password "security" - was"Passwords with Lan Manager (LM) under Windows" and "Whitespace in passwords""
    To: pen-test@securityfocus.com
    Date: Wed, 28 Sep 2005 13:02:42 -0400
    
    

    OAT is another good one for Oracle checks (www.cqure.net)

    >From: "Josh Perrymon" <perrymonj@networkarmor.com>
    >To: "Massimo" <massimo.mail@quipo.it>, <pen-test@securityfocus.com>
    >Subject: RE: oracle VA/PT
    >Date: Wed, 28 Sep 2005 06:02:43 -0500
    >
    >Sorry,
    >
    >Got my tools mixed up. Absinthe is for SQL injection-
    >
    >MetaCoretex will do the Oracle checks.
    >
    >jP
    >
    >-----Original Message-----
    >From: Massimo [mailto:massimo.mail@quipo.it]
    >Sent: Tuesday, September 27, 2005 12:07 AM
    >To: pen-test@securityfocus.com
    >Subject: oracle VA/PT
    >
    >Hi to all.
    >
    >Some day ago I was quite surprised to see that on a server that was
    >scanned with nessus and with emaze scanner that revealed no relevant
    >security hole, there was oracle installed and active with all the
    >default oracle user/password activated (i.e. system/manager,
    >scott/tiger, etc).
    >
    >What VA tool can find default user on oracle? Is it possible to find
    >that info with Nessus (perhaps I can't use it at its best)?
    >
    >Best Regards,
    > Massimo
    >PS
    >I usually activate all the check on nessus and emaze.
    >
    >------------------------------------------------------------------------
    >------
    >Audit your website security with Acunetix Web Vulnerability Scanner:
    >
    >Hackers are concentrating their efforts on attacking applications on
    >your
    >website. Up to 75% of cyber attacks are launched on shopping carts,
    >forms,
    >login pages, dynamic content etc. Firewalls, SSL and locked-down servers
    >are
    >futile against web application hacking. Check your website for
    >vulnerabilities
    >to SQL injection, Cross site scripting and other web attacks before
    >hackers do!
    >Download Trial at:
    >
    >http://www.securityfocus.com/sponsor/pen-test_050831
    >------------------------------------------------------------------------
    >-------
    >
    >
    >
    >
    >
    >------------------------------------------------------------------------------
    >Audit your website security with Acunetix Web Vulnerability Scanner:
    >
    >Hackers are concentrating their efforts on attacking applications on your
    >website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    >login pages, dynamic content etc. Firewalls, SSL and locked-down servers
    >are
    >futile against web application hacking. Check your website for
    >vulnerabilities
    >to SQL injection, Cross site scripting and other web attacks before hackers
    >do!
    >Download Trial at:
    >
    >http://www.securityfocus.com/sponsor/pen-test_050831
    >-------------------------------------------------------------------------------
    >

    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner:

    Hackers are concentrating their efforts on attacking applications on your
    website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for vulnerabilities
    to SQL injection, Cross site scripting and other web attacks before hackers do!
    Download Trial at:

    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------


  • Next message: dave kleiman: "RE: Password "security" - was"Passwords with Lan Manager (LM) under Windows" and "Whitespace in passwords""

    Relevant Pages

    • RE: MS SQL, find list of tables
      ... connected to the Access ODBC driver. ... MS SQL, find list of tables ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)
    • Re: SQL Server Password Cracker/Guesser
      ... >> Can anyone tell me what they are using to crack/guess SQL Server ... >> Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ... Cross site scripting and other web attacks before hackers ...
      (Pen-Test)
    • RE: MS SQL Server (cracking accounts)
      ... keep track of their SQL instances and how many have SA=blank ... >Audit your website security with Acunetix Web Vulnerability Scanner: ... >Hackers are concentrating their efforts on attacking ... Up to 75% of cyber attacks are launched on shopping ...
      (Pen-Test)
    • Re: oracle VA/PT
      ... You can get OAT (oracle auditing tool) at cqure.net ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... > Hackers are concentrating their efforts on attacking applications on ... Up to 75% of cyber attacks are launched on shopping ...
      (Pen-Test)
    • RE: MS SQL, find list of tables
      ... Funny thing is that MS ACCESS in a weird way is more a pain to SQL inject than SQL Server and Oracle. ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ... Este mensaje electrónico puede contener información confidencial o privilegiada, ...
      (Pen-Test)