<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-435733304176172126</id><updated>2026-05-06T11:56:04.806+01:00</updated><category term="security"/><category term="DBMS_JVM_EXP_PERMS"/><category term="FAILED_LOGIN_ATTEMPTS"/><category term="PASSWORD_LIFE_TIME"/><category term="PASSWORD_VERIFY_FUNCTION"/><category term="Responsible disclosure"/><category term="SQL92_SECURITY"/><category term="oracle"/><category term="passwords"/><title type='text'>FifteenTwentyOne - Oracle security without obscurity</title><subtitle type='html'>The rants of a Oracle Database Security Consultant. &#xa;1521 is the unofficial port of the Oracle database listener.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.fifteentwentyone.co.uk/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/435733304176172126/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://blog.fifteentwentyone.co.uk/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Simon Fletcher</name><uri>http://www.blogger.com/profile/09412451086711899558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvY-s_m52rbZL0hrhar1DAhnLxmQHKLWSdetzT093-YXPTJWuiPf8QPxditpEEckJRd8DB6clohvlTnCHdiO0KKpm6PKEo3maXr37HvMH8upj-XYt7nZpI17oZoDh_/s220/vt220invader2_icon_64x64.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-435733304176172126.post-8677968639065916335</id><published>2010-02-20T09:30:00.001+00:00</published><updated>2010-02-20T15:59:57.972+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="oracle"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="SQL92_SECURITY"/><title type='text'>SQL92_SECURITY</title><summary type="text">The Oracle database initialization parameter SQL92_SECURITY is an often overlooked security parameter. Either because people don&#39;t understand it or because they think it&#39;s irrelevant.So what does it do? Well, to quote the documentation:&quot;The SQL92 standards specify that security administrators should be able to require that users have SELECT privilege on a table when executing an UPDATE or DELETE </summary><link rel='replies' type='application/atom+xml' href='http://blog.fifteentwentyone.co.uk/feeds/8677968639065916335/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.fifteentwentyone.co.uk/2010/02/sql92security.html#comment-form' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/435733304176172126/posts/default/8677968639065916335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/435733304176172126/posts/default/8677968639065916335'/><link rel='alternate' type='text/html' href='http://blog.fifteentwentyone.co.uk/2010/02/sql92security.html' title='SQL92_SECURITY'/><author><name>Simon Fletcher</name><uri>http://www.blogger.com/profile/09412451086711899558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvY-s_m52rbZL0hrhar1DAhnLxmQHKLWSdetzT093-YXPTJWuiPf8QPxditpEEckJRd8DB6clohvlTnCHdiO0KKpm6PKEo3maXr37HvMH8upj-XYt7nZpI17oZoDh_/s220/vt220invader2_icon_64x64.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwwknbqwi9Mj_Fuc-YxNEXEweVxBOBcWnTEpc6Jmwhtdir5Ta3PzTNx9lp3xfUTDpscT-TgzBnRvT-VKi0xm2_5zMVQWmeNtilJUFSdXuMwtHjTRgxEIkZpFdvYzr73_Xqb5aR83XyCsU/s72-c/sql92.png" height="72" width="72"/><thr:total>14</thr:total></entry><entry><id>tag:blogger.com,1999:blog-435733304176172126.post-5742479665116961950</id><published>2010-02-08T13:23:00.019+00:00</published><updated>2010-02-09T10:51:28.018+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DBMS_JVM_EXP_PERMS"/><category scheme="http://www.blogger.com/atom/ns#" term="Responsible disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><title type='text'>Responsible disclosure!</title><summary type="text">David Litchfield of NGS Software recently gave a presentation at Black Hat DC 2010 entitled &quot;Hacking Oracle11g&quot;. In this presentation he discloses a couple of vulnerabilities that allow an unprivileged database user to execute arbitrary commands on the database host. In Linux/Unix environments this mean running commands as the Oracle owner (normally &quot;oracle&quot;) and on Windows environments as &quot;</summary><link rel='replies' type='application/atom+xml' href='http://blog.fifteentwentyone.co.uk/feeds/5742479665116961950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.fifteentwentyone.co.uk/2010/02/responsible-disclosure.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/435733304176172126/posts/default/5742479665116961950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/435733304176172126/posts/default/5742479665116961950'/><link rel='alternate' type='text/html' href='http://blog.fifteentwentyone.co.uk/2010/02/responsible-disclosure.html' title='Responsible disclosure!'/><author><name>Simon Fletcher</name><uri>http://www.blogger.com/profile/09412451086711899558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvY-s_m52rbZL0hrhar1DAhnLxmQHKLWSdetzT093-YXPTJWuiPf8QPxditpEEckJRd8DB6clohvlTnCHdiO0KKpm6PKEo3maXr37HvMH8upj-XYt7nZpI17oZoDh_/s220/vt220invader2_icon_64x64.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFpCggb_UKqjWXK4Fp_8mAKMzKs0pLNbbOIlN4LkzUK-Q1uy4FIuDCWfAP7IbpiQMqCnZp-fQkLE8_9fenE8fkAksBGggDbd0hfT0VuXD-rIZNuOpwgQbYEVF5GdqI7siTFWb7Au1aV5Q/s72-c/gagged.png" height="72" width="72"/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-435733304176172126.post-3424168208930240527</id><published>2009-11-27T08:54:00.014+00:00</published><updated>2010-02-09T10:45:11.215+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="FAILED_LOGIN_ATTEMPTS"/><category scheme="http://www.blogger.com/atom/ns#" term="PASSWORD_LIFE_TIME"/><category scheme="http://www.blogger.com/atom/ns#" term="PASSWORD_VERIFY_FUNCTION"/><category scheme="http://www.blogger.com/atom/ns#" term="passwords"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><title type='text'>Database profiles</title><summary type="text">My first rant on this blog might as well be one of my favourites, although regrettably a bit long...  I frequently see on customer sites database profiles implemented for application users but not for database administrators or default accounts (e.g. SYS &amp;amp; SYSTEM).  Okay basic refresh: Database profiles enforce resource and password restrictions on database user accounts.  It’s these password</summary><link rel='replies' type='application/atom+xml' href='http://blog.fifteentwentyone.co.uk/feeds/3424168208930240527/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://blog.fifteentwentyone.co.uk/2009/11/database-profiles.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/435733304176172126/posts/default/3424168208930240527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/435733304176172126/posts/default/3424168208930240527'/><link rel='alternate' type='text/html' href='http://blog.fifteentwentyone.co.uk/2009/11/database-profiles.html' title='Database profiles'/><author><name>Simon Fletcher</name><uri>http://www.blogger.com/profile/09412451086711899558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvY-s_m52rbZL0hrhar1DAhnLxmQHKLWSdetzT093-YXPTJWuiPf8QPxditpEEckJRd8DB6clohvlTnCHdiO0KKpm6PKEo3maXr37HvMH8upj-XYt7nZpI17oZoDh_/s220/vt220invader2_icon_64x64.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZOln5QgJSFJzhpVdB-ixIE1BSUAfPYF9cC_Hs-s1ZGeX-gNbHLummZC7vsPWqKxRMnMnZ0gFKPJTt6gIH2P-DGfJRZI94xUiSSMr9f_zmd8Uk1D12qmdGg4Rh9DsuM0MvPoMkskjTYbE/s72-c/ora-01017.png" height="72" width="72"/><thr:total>2</thr:total></entry></feed>