Advertisement
Promo

Application development Toolkit

Bugs bust open 'unbreakable' Oracle 9i

Published: 07 Feb 2002 11:21 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security researcher will detail a bevy of software flaws in Oracle's flagship database at the Black Hat Windows Security Briefings in New Orleans this week, busting up the company's promise that the program is "unbreakable."

The security problems, found by UK security researcher David Litchfield in December, include a serious software slip-up that could let hackers take control of corporate servers loaded with the database program.

"This is a very serious problem for organisations that rely on Oracle," Litchfield said in a statement on Wednesday. "Those that don't take steps to protect themselves will be left open to severe attacks such as data theft or modification."

The problems highlight the danger in claiming that software products are totally secure, said Greg Shipley, director of consulting services for security firm Neohapsis.

"It's the classic way of doing marketing wrong, and it puts a big target on your products," he said.

Normally, companies adopt a flock-of-sheep mentality, keeping their heads down and, hopefully, out of sight of the online wolves that roam the Internet. Companies that throw down the gauntlet to hackers usually find themselves in trouble, said Shipley. "Name one vendor that hasn't been taken down. They all have."

However, Oracle's chief security officer Mary Ann Davidson took exception with any characterisation that the company hasn't delivered on its promise to create "unbreakable" software.

"We are doing a heck of a lot," she said. "I would much rather stand up and say we are going to make every product unbreakable than to say, 'you're right, it's impossible,' and give up."

With tag lines such as "Oracle9i Database -- Can't Break It. Can't Break In" and "Only Oracle9i Is Unbreakable," the company's marketing campaign -- kicked off at Comdex in Las Vegas last November -- has set a high bar for the database maker's programmers. Oracle has spent more than a million dollars on international software certifications that require a minimum level of security.

Even so, security experts have criticised the marketing campaign as so much fluff.

"The whole 'unbreakable' thing is not possible, given current technology," said Chris Wysopal, director for research and development at network-protection firm @Stake. "All software has holes."

He did give Oracle kudos for taking security seriously. "Look at the actions," he said. "Don't look at the marketing slogans."

Oracle's Davidson acknowledged that the company may come under fire for its marketing pledge, but in the end, she added it's not about not having software flaws -- it's about a company's commitment to do away with those flaws that matters.

"Everyone should be taking a pledge to make their products unbreakable," she said, adding that companies that accept the status quo, putting security in second place, have no place in the enterprise.

The glitch in Oracle's marketing message comes two weeks after a memo from Microsoft chairman Bill Gates told the software giant's employees to make security the No. 1 priority.

Oracle, like Microsoft, has had its share of security holes. Last July, security researchers found a software bug in the company's 8i database that could let malicious attackers break into its servers.

The current set of flaws found by Litchfield, a consultant with Next Generation Security Software, were discovered when the researcher tested a vulnerability assessment scanner against Oracle's latest database software.

The software bugs occur in Oracle's database and Java-server modules for the Apache Web software. Oracle published software patches for some of the flaws in December and for the rest of the flaws on Wednesday.

"Marketing campaigns come and go," said Oracle's Davidson, "but we are in security for the long haul."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
37 out of 63 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Video icon

Video

Discussions

manek manek

Time for your baggage to arrive, then

Monday 30 November 2009, 12:44 PM

1 comment
siarad siarad

Reply

Monday 30 November 2009, 10:43 AM

8 comments

Featured Talkback

In association with Network Liberation Movement
The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters