Most Popular Stories
- One on One with Arpan Shah of Microsoft Sharepoint
- IBM will snag half of India's outsoucing work by 2010
- Vendors prepare for Obama's electronic medical records change
- Teen sends 14,528 text messages in a single month
- Coke uses RFID for drink dispensers
- Forrester report predicts web content management will grow in spite of economy
Events
- CTO Telecom Summit
Nov 8-11, 2009 — Four Seasons Resort – Scottsdale, AZ
Sponsored Links
Free Newsletter
Latest News
Popular Topics
Whitepapers
Oracle exploits coming at Black Hat DC 2007
Looks like Oracle is going to be taken to task for security yet again. At Black Hat DC 2007, starting tomorrow here in the nation's capital, major Oracle exploits are set to be unveiled during two Oracle-centric presentations: "Advanced Oracle Attack Techniques" with security researcher David Litchfield and "Practical 10 Minute Security Audit: The Oracle Case" with Argeniss founder Cesar Cerrudo. Black Hat has long been a thorn in Oracle's side; many of you will recall that Litchfield revealed an unpatched Oracle flaw at Black Hat 2006 that drew the database company's ire. Cerrudo is expected to release "at least one zero-day vulnerability and exploit code," while Litchfield is set to demonstrate a new exploit based on a recently published security paper that's making waves in the security community. "Any new buffer overflow vulnerability does nothing to further the knowledge base of the security community, and it only serves to increase risk [to users]," Lindstrom said. "In cases where there are entire new classes of attack, where you're learning a whole new technique, rather than throwing a whole lot of data at a process and waiting for it to break--which everyone and their grandmother could do--…you're learning about new ways in which applications can be exploited."
For more on the coming exploits:
- see this eWeek article
Related Stories
- Firefox 2/IE 7 animated cursor exploit on the way
- Mozilla to issue workaround for .ANI bug
- Vista exploits for sale
- Hackers exploiting unpatched Windows DNS bug
- Zero-day bugs remain after Microsoft Patch Tuesday
- New Microsoft Word zero-day attack on the loose
- Symantec: Vista vulnerable to legacy exploits
- Mac OS X to get its own zero-day response team?
- Vista exploit: Annoying MySpace pages a threat?
- Windows flaw gets critical, patch coming tomorrow
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2009 FierceMarkets, Inc. All rights reserved. |
![]() |







Click here to get the FierceCIO:TechWatch email newsletter for FREE!
Be the first to comment