ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

More flaws found in Oracle security

Joris Evers CNET News.com

Published: 28 Oct 2005 07:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Attackers could easily uncover Oracle database users' passwords because of a weak protection mechanism, putting corporate data at risk of exposure, experts have warned.

In the latest critique of Oracle's security practices, experts are calling on the software maker to improve the mechanism used to secure passwords for database users. Researchers say they have found a way to recover the plain text password from even very strong, well-written Oracle database passwords within minutes.

The technique Oracle uses to store and encrypt user passwords doesn't provide sufficient security, said Joshua Wright of the SANS Institute and Carlos Sid of Royal Holloway College, University of London. Wright gave a presentation on the matter Wednesday at the SANS Network Security conference in Los Angeles.

In the presentation, Wright discussed how passwords are encrypted before being stored in Oracle databases and presented a tool he wrote to uncover passwords, according to a SANS statement. A paper by Wright and Cid is available on the SANS Web site. (Download PDF.)

Wright and Cid identified several vulnerabilities, including a weak hashing mechanism and a lack of case preservation--all passwords are converted to uppercase characters before calculating the hash.

"By exploiting these weaknesses, an adversary with limited resources can mount an attack that would reveal the plain text password from the hash for a known user," Wright and Cid wrote in their paper.

The researchers informed Oracle about their findings in July, but subsequent requests for a response from Oracle have gone unanswered, according to SANS. Oracle also did not respond to a request for comment from CNET News.com.

Oracle users can protect their systems by requiring strong passwords and assigning limited user rights, the researchers said. Users are also encouraged to tell Oracle that it should improve password protection, they wrote.

Oracle is increasingly coming under fire for its security practices. Security researchers have taken the company to task for being slow in fixing security vulnerabilities and providing faulty patches when it does update its software.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
92 out of 178 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Application Architect

This role defines best practices in the critical evaluation and selection and / or development of the software components and hardware requirements ...

IBM Maximo Solution Architect

This role defines best practices in the critical evaluation and selection and / or development of the software components and hardware requirements ...

Leading Data architect for top hedge fund city based

The candidate is required to understand & apply industry best practices in data architecture, data modeling and database design. In depth knowledge ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments