New worm variant exploits Oracle errors
The malicious code has the ability to exploit security vulnerabilities and cause serious damage to previously distributed Oracle database software that has been widely modified and redistributed on the Internet, ringing a scene ring. New report about a new attack.
Thus, just two months after an unnamed researcher first published an example of an attack computer worm exploiting a security vulnerability in Oracle database software, this malicious code was researched and improved to redistribute through the list of Full Disclosure email. Again a new technique to attack this database system.
However, Alexander Kornbrust, executive director of database security firm GmbH, said: 'These kinds of attacks are still theoretical and I don't think that the applications The database may be threatened because of risks like this. If you are managing a large company with hundreds of valuable databases, this code is really a destroyer. This malicious code is likely to be used to develop into a complete worm. Being careful is probably the best thing to do '
Kornbrust - an expert well known for Oracle's security research products - thinks he has also created a real attack method that uses the default username and password in the engine. Oracle database.
Aaron Newman, senior technology engineer at Application Security Inc., described this new code as something "much more advanced" than the previous code. ' However, it still lacks practical applicability to spread widely even though they themselves are capable .'
Kornbrust recommends that database administrators need to be cautious about the risk of attacks based on security vulnerabilities on workstations plus dangerous code exploiting Oracle's security flaws. ' A successful attack can target database applications through a Windows vulnerability, gaining system access to using Oracle worms to cause serious damage. '
You should read it
- Oracle launched an autonomous database exclusively for business customers
- How to Study Oracle
- How to Become an Oracle Consultant
- How to Use R Language to Connect with an ORACLE Database
- Oracle announced Exadata version 2
- Compare the performance of MongoDB and SQL Server 2008
- Database management with TOAD
- What is Oracle VirtualBox? What can be done with it?
May be interested
- How to Become an Oracle Consultantoracle is one of the biggest integrated hardware and software businesses in the world, with forty percent of the international database market. oracle provides advanced applications for businesses, most notably, customer relationship...
- Learn About Accent Oracle: AI That Can Predict Accents With Extreme Accuracyeven if you think your accent is too good to be detected, accent oracle can prove you wrong.
- Tool to destroy the Conficker worm variant for freethe new variant of conficker (downadup) continues to multiply exponentially, making many people afraid to access the internet and browse the web.
- D32 Virus Removal Software updates new viruses on December 25, 2004d32 software (december 25, 2004) updates the viruses dob2k.worm.w32, dotnet.worm.w32, ebscam.htm.trj.w32, elizabeth.worm.w32, hydra.exe.worm.w32, hydra. gen.worm.w32, invalidssl.worm.w32, netsky.ag.exe.worm.w32, netsky.ag.gen.worm.w32, outa2k.worm.w32 and zombie.gen.worm.w32.
- Microsoft and Oracle, along with the 'matching swords' against Amazon in the cloud computing battlemicrosoft and oracle - the two giant service providers of the cloud computing market - recently said they have reached an important joint cooperation agreement.
- Oracle Database 11g set a new world recordoracle has announced a world record for tpc-h 3-terabyte standard test results for oracle 11g databases on oracle's sun sparc enterprise m9000 single server
- Virus appears to attack Twitter userskaspersky lab experts have issued a warning about a new worm that attacks twitter accounts. this worm exploits the google provider path shortening service goo.gl.
- New variant Gozi Trojan raged againsince april 17, there have been more than 2,000 home users falling victim to the latest variant of gozi data theft trojan. the new gozi variant has been rated extremely dangerous with new upgrades and equipped with the ability to hide itself more highly in the face of.
- Oracle announced Exadata version 2the world's first online transaction processing database has been announced by oracle ceo and sun's senior vice president
- Oracle wants to turn Java EE into fully open sourcethis week, oracle announced plans to move java ee project management to an open source platform, like apache or eclipse.