knowledge is security
Showing 1 - 1 of 1 RSS Feed

Files

create_any_directory_to_sysdba.pdf
Posted Oct 13, 2008
Authored by Paul Wright | Site oracleforensics.com

An Oracle DB user which has been granted CREATE ANY DIRECTORY can use that system privilege to grant themselves the SYSDBA system privilege by creating a DIRECTORY pointing to the password file location on the OS and then overwriting it with a previously prepared known binary password file using UTL_FILE.PUT_RAW from within the DB. This paper will show how the issue can be exploited and most importantly how to secure against it.

tags | paper
MD5 | 404bf158718bb3d6e609975690deb646
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close