Go Back   vBulletin Setup > General Forums > General Discussion > Computer Tech Information


Please Register to get full access to the forums.
Post New Thread  Reply



#1   08-28-2006, 11:59 PM
Send a message via AIM to Brandon Send a message via MSN to Brandon Send a message via Yahoo to Brandon Brandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of light Join Date: Jul 2006 Posts: 9,961 Location: Topeka, KS
Black Hat: U.K. security guru lays into database vendors


David Litchfield reveals another clutch of Informix holes


August 07, 2006 -- Noted security researcher David Litchfield has again panned the state of database security, revealing another clutch of vulnerabilities in the software of a major vendor.
In his address at the Black Hat conference in Las Vegas this week, he released details of more than 20 holes that he and his researchers at U.K.-based Next Generation Security Software Ltd. had uncovered in IBM's Informix database family.

The wide-ranging flaws could allow an attacker to mount a denial-of-service attack, gain access to information or simply compromise the integrity of the database itself. Versions 7.3, 9.4, and 10.0. are said to be affected.

Security Web site Secunia has since released more details of most of these vulnerabilities, which it rates as "moderately critical".

"In my opinion, database security is riddled with holes and it's the biggest problem we face in IT today," Litchfield was reported to have said during the presentation.

"The database attacks are out there and these data breaches show it. They just aren't noticed at the time."

Litchfield has excellent database flaw-finding credentials, having been responsible for finding a large number in the products of Oracle two years ago.
He subsequently pursued the company over the time it took to patch one of these holes, which Litchfield said was significant. He even went to the unusual lengths of releasing his own patch for the issue.

He remains angered by the time it takes database vendors to patch reported flaws, commenting on the number of issues that remained to be dealt with in the products of his favorite target, Oracle.

(TechWorld.com)
--------------------
Brandon Sheley / vBulletin Setup Staff
Check out our Newsletter for the latest vB and SEO news.
Are you looking for vBulletin work to be done on your forums ?
Would you like to Help Support vBulletin Setup.

Please do not PM me for support, that's what the forums are for.
Have you heard about Crowdgather?
Find it on Forums


Stay up to date by installing our Tool Bar
Quote   |  
Post New Thread  Reply
vBulletin Setup > General Forums > General Discussion > Computer Tech Information


Thread Tools
Display Modes

 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Blog Security and set up? joshbond Blogging Forum 5 07-18-2007 09:15 PM
Google Turns to Security News Search Engine News 0 07-10-2007 11:01 PM
Trend Micro PC-cillin Internet Security 2006 Brandon Computer Tech Information 2 08-20-2006 02:07 AM
Yahoo Plugs Security Hole in Web Mail Service Brandon Search Engine News 0 08-16-2006 09:13 PM


All times are GMT -6. The time now is 12:50 AM.

vBulletin Setup, vBulletin Setup Forums, vBulletin Services, vBulletin Blogs, vBulletin SEO, vBulletin Questions, vBulletin Skins, Styles, Templates
vBulletin Hacks / Modifications, vBulletin Monetization, Blogs, vBulletin Link Directory,Quality Link Directory