<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Musings on Database Security</title>
	
	<link>http://www.slaviks-blog.com</link>
	<description>Slavik's Blog</description>
	<lastBuildDate>Sat, 06 Feb 2010 19:45:04 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/slaviks-blog/WxxD" /><feedburner:info uri="slaviks-blog/wxxd" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><feedburner:emailServiceId>slaviks-blog/WxxD</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Salesforce errors</title>
		<link>http://feedproxy.google.com/~r/slaviks-blog/WxxD/~3/rCAY5kxY31s/</link>
		<comments>http://www.slaviks-blog.com/2010/02/06/salesforce-errors/#comments</comments>
		<pubDate>Sat, 06 Feb 2010 19:45:04 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[technical tips]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=223</guid>
		<description>As part of my continued crusade to get rid of all database errors returned from the application to the user, one of our developers sent me the following error message coming from Salesforce.com:

SF Error


So, what can we learn from the error?

SF uses Java as a backend
SF uses Oracle as the database
The application is programmed using [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?a=rCAY5kxY31s:p0Gl6-oYD-4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/slaviks-blog/WxxD/~4/rCAY5kxY31s" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/02/06/salesforce-errors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.slaviks-blog.com/2010/02/06/salesforce-errors/</feedburner:origLink></item>
		<item>
		<title>David Lichtfield in the Oracle cross-hairs (again…)</title>
		<link>http://feedproxy.google.com/~r/slaviks-blog/WxxD/~3/kSm3gq-AEM4/</link>
		<comments>http://www.slaviks-blog.com/2010/02/03/david-lichtfield-in-the-oracle-cross-hairs-again%e2%80%a6/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 02:18:23 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[MS SQL Server]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=221</guid>
		<description>Yesterday at Black Hat, David released information on his latest find, a pretty serious batch of vulnerabilities in Oracle 11g which allows any user to escalate privileges to gain complete access &amp;#38; control of the database.
What’s interesting here is not so much that there is yet another vulnerability  (for those of you who are running [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?a=kSm3gq-AEM4:EwVYHHU3dAU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/slaviks-blog/WxxD/~4/kSm3gq-AEM4" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/02/03/david-lichtfield-in-the-oracle-cross-hairs-again%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.slaviks-blog.com/2010/02/03/david-lichtfield-in-the-oracle-cross-hairs-again%e2%80%a6/</feedburner:origLink></item>
		<item>
		<title>Scanning random IPs for Oracle Listener</title>
		<link>http://feedproxy.google.com/~r/slaviks-blog/WxxD/~3/8MkME95B4rA/</link>
		<comments>http://www.slaviks-blog.com/2010/01/29/scanning-random-ips-for-oracle-listener/#comments</comments>
		<pubDate>Sat, 30 Jan 2010 00:02:56 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=217</guid>
		<description>Dennis wrote an interesting blog entry about an experiment he conducted.
He found that out of roughly every 69,000 randomly scanned IP addresses, there is one open Oracle TNS Listener. That&amp;#8217;s interesting because we all know that there are numerous attacks on (even fully patched) listeners that do not require any authentication.
Looking at the listener versions, you can [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?a=8MkME95B4rA:hMmg3KV4DQM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/slaviks-blog/WxxD/~4/8MkME95B4rA" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/01/29/scanning-random-ips-for-oracle-listener/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.slaviks-blog.com/2010/01/29/scanning-random-ips-for-oracle-listener/</feedburner:origLink></item>
		<item>
		<title>Oracle January 2010 CPU</title>
		<link>http://feedproxy.google.com/~r/slaviks-blog/WxxD/~3/7Yitc6JzJFo/</link>
		<comments>http://www.slaviks-blog.com/2010/01/13/oracle-january-2010-cpu/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 23:20:20 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[cpus]]></category>
		<category><![CDATA[virtual_patching]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=214</guid>
		<description>Ah, time flies when you&amp;#8217;re having fun. It seams that only yesterday we worked on the October CPU and now Oracle released the January CPU.
This time, Oracle acknowledged 24 security fixes, 9 of them in the database layer. This number is a bit lower than the average but as in the previous CPU, you have [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?a=7Yitc6JzJFo:epeAdOyLR-o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/slaviks-blog/WxxD/~4/7Yitc6JzJFo" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/01/13/oracle-january-2010-cpu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.slaviks-blog.com/2010/01/13/oracle-january-2010-cpu/</feedburner:origLink></item>
		<item>
		<title>Tapulous MySQL Error and SQL Injection vulnerability</title>
		<link>http://feedproxy.google.com/~r/slaviks-blog/WxxD/~3/pcxrVUbZRyY/</link>
		<comments>http://www.slaviks-blog.com/2010/01/06/tapulous-mysql-error-and-sql-injection-vulnerability/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 06:36:08 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[MySQL]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=205</guid>
		<description>I&amp;#8217;ve talked about displaying errors from the database on the user screen a while ago. In my opinion, this is definitely a big no-no and a security problem just waiting to happen.
As some of you know, I have an iPhone (and I like it a lot, but that&amp;#8217;s another story). I&amp;#8217;ve installed a nice little [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?a=pcxrVUbZRyY:zikh-S6Tr5g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/slaviks-blog/WxxD/~4/pcxrVUbZRyY" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/01/06/tapulous-mysql-error-and-sql-injection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.slaviks-blog.com/2010/01/06/tapulous-mysql-error-and-sql-injection-vulnerability/</feedburner:origLink></item>
		<item>
		<title>Getting closer to a national breach notification law</title>
		<link>http://feedproxy.google.com/~r/slaviks-blog/WxxD/~3/kzOrgdZhXaI/</link>
		<comments>http://www.slaviks-blog.com/2010/01/04/getting-closer-to-a-national-breach-notification-law/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 22:14:56 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[sb1386]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=210</guid>
		<description>In the midst of all the excitement around healthcare reform, the fact that both the house and senate made some progress on their (separate) bills for protecting personal information hasn’t received the attention it deserves.  Sure, I think we’re up to 46 states that now have their own breach notification laws, but simplifying this and [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?a=kzOrgdZhXaI:vHJm0qA8CBg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/slaviks-blog/WxxD?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/slaviks-blog/WxxD/~4/kzOrgdZhXaI" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/01/04/getting-closer-to-a-national-breach-notification-law/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.slaviks-blog.com/2010/01/04/getting-closer-to-a-national-breach-notification-law/</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic Page Served (once) in 0.631 seconds --><!-- Cached page served by WP-Cache -->
