ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

Bugs bust open 'unbreakable' Oracle 9i

Published: 07 Feb 2002 11:21 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security researcher will detail a bevy of software flaws in Oracle's flagship database at the Black Hat Windows Security Briefings in New Orleans this week, busting up the company's promise that the program is "unbreakable."

The security problems, found by UK security researcher David Litchfield in December, include a serious software slip-up that could let hackers take control of corporate servers loaded with the database program.

"This is a very serious problem for organisations that rely on Oracle," Litchfield said in a statement on Wednesday. "Those that don't take steps to protect themselves will be left open to severe attacks such as data theft or modification."

The problems highlight the danger in claiming that software products are totally secure, said Greg Shipley, director of consulting services for security firm Neohapsis.

"It's the classic way of doing marketing wrong, and it puts a big target on your products," he said.

Normally, companies adopt a flock-of-sheep mentality, keeping their heads down and, hopefully, out of sight of the online wolves that roam the Internet. Companies that throw down the gauntlet to hackers usually find themselves in trouble, said Shipley. "Name one vendor that hasn't been taken down. They all have."

However, Oracle's chief security officer Mary Ann Davidson took exception with any characterisation that the company hasn't delivered on its promise to create "unbreakable" software.

"We are doing a heck of a lot," she said. "I would much rather stand up and say we are going to make every product unbreakable than to say, 'you're right, it's impossible,' and give up."

With tag lines such as "Oracle9i Database -- Can't Break It. Can't Break In" and "Only Oracle9i Is Unbreakable," the company's marketing campaign -- kicked off at Comdex in Las Vegas last November -- has set a high bar for the database maker's programmers. Oracle has spent more than a million dollars on international software certifications that require a minimum level of security.

Even so, security experts have criticised the marketing campaign as so much fluff.

"The whole 'unbreakable' thing is not possible, given current technology," said Chris Wysopal, director for research and development at network-protection firm @Stake. "All software has holes."

He did give Oracle kudos for taking security seriously. "Look at the actions," he said. "Don't look at the marketing slogans."

Oracle's Davidson acknowledged that the company may come under fire for its marketing pledge, but in the end, she added it's not about not having software flaws -- it's about a company's commitment to do away with those flaws that matters.

"Everyone should be taking a pledge to make their products unbreakable," she said, adding that companies that accept the status quo, putting security in second place, have no place in the enterprise.

The glitch in Oracle's marketing message comes two weeks after a memo from Microsoft chairman Bill Gates told the software giant's employees to make security the No. 1 priority.

Oracle, like Microsoft, has had its share of security holes. Last July, security researchers found a software bug in the company's 8i database that could let malicious attackers break into its servers.

The current set of flaws found by Litchfield, a consultant with Next Generation Security Software, were discovered when the researcher tested a vulnerability assessment scanner against Oracle's latest database software.

The software bugs occur in Oracle's database and Java-server modules for the Apache Web software. Oracle published software patches for some of the flaws in December and for the rest of the flaws on Wednesday.

"Marketing campaigns come and go," said Oracle's Davidson, "but we are in security for the long haul."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
36 out of 62 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

User Experience Researcher London - 50k

Key Client of Huxley Associates is currently looking for an experienced User Experience Researcher to perform the following duties: -Develop and ...

SAS Senior Insight Analyst -- London / South East -- SAS / SQL

Not just a statistical role however, the successful candidate will use this analysis to help form marketing campaign and help solve complex business ...

Senior Quantitative Researcher, Equity Algorithmic Trading Hedge Fund

A leading European Hedge Fund is looking for an experienced Quantitative Researcher to join the team. This fund has a number of offices around the ...

Discussions

pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling