A new attack technique increases the risk of commonly found bugs in Oracle's database software, a security researcher has warned. It was previously thought that an attacker needed high-level privileges on the database to exploit so-called PL SQL injection vulnerabilities. With a new attack technique, that's no longer true, David Litchfield, a database security expert with NGS Software, said on Thursday at the Black Hat DC event here. . "It is a trick that can be used by attackers with minimal privileges to gain complete control of the database server," Litchfield said in an interview. "You can use the trick through a large number of vulnerabilities that were previously thought not to be that significant." . Latest methods enable intruders slight entry points to take advantage of critical vulnerabilities in Oracle database applications.. Oracle Database Exploits, Attack Techniques, Database Security Risks. . LinuxSecurity.com Team
Borland's InterBase database software contains a "back door" that allows anyone with the appropriate password to wreak major havoc with the database and the computer it's running on, security experts said. A back door is an undocumented way to get access . . . . Borland's InterBase database software contains a "back door" that allows anyone with the appropriate password to wreak major havoc with the database and the computer it's running on, security experts said. A back door is an undocumented way to get access to a computer system, typically using a secret password. In this case, the back door lets an attacker change the information stored in an InterBase database and insert programs that could enable even more damaging actions, according to an advisory posted Wednesday by the Computer Emergency Response Team. The link for this article located at News.com is no longer available. . Security analysts warn of a potential back door access threat linked to vulnerabilities in the InterBase database system, posing risks to numerous databases and associated infrastructures.. Borland InterBase, Database Security, Backdoor Exploit, Cybersecurity Risk. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.