Home
Pentest White Papers

The White Papers presented on this page have been written by Pentest Consultants for various forums, user groups and seminars and for the general security community.

Click to expand Security Scans

Click to expand Wireless

Click to contract Oracle
 Article Description
HTML PDF Exploiting And Protecting Oracle

This major paper gives an overview of how to hack into Oracle and where the vulnerabilities lie covering all of the main parts of the RDBMS and associated tools pointing out potentially exploitable vulnerabilities. Also discussed briefly are SQL techniques for finding out what is in the database, where it is, how it's structured, how the database is protected, what to read, what permissions you have when you get an account and how to see and interpret the audit trail.

 
HTML PDF Extracting Clear Text Passwords from the SGA

This paper is a posting made to www.securityfocus.com to show how incorrect setting of the Oracle parameter utl_file_dir can be exploited to read clear text passwords from the Oracle SGA.

 
HTML PDF Oracle Default User and Password List

This paper contains a table of default Oracle users, passwords and hashes. This table will be updated with any new default users and passwords as they become available. Pentest invites anyone to contribute with any new default users that are not included at present. Please email Pentest:oracle with any new data.

 
HTML PDF Issues with the initialisation parameter fixed date

This short paper describes the issues that can arise if an Oracle application uses the system date SYSDATE for critical functionality and if it's possible for an attacker to alter the initialisation parameter fixed_date.

 
HTML PDF Have your objects been tampered with ?

Interesting title!
Have you ever wanted to check if users are tampering with your Oracle PL/SQL source code stored within the database itself or even added or changed database objects? You can buy third party products to do this for the operating system files but how would you do it for your database objects ?

 
HTML PDF Some thoughts on Oracle Passwords

This article discusses a few ideas on how to make Oracle passwords that bit more secure.


Click to expand Presentations

Click to expand Embedded/ARM

Click to expand Other Papers