Penetration Testing mailing list archives
RE: oracle VA/PT
From: Michael Gargiullo <mgargiullo () pvtpt com>
Date: Tue, 27 Sep 2005 14:55:23 -0400
I find it strange that nessus didn't even see an open port on 1421. There is a commercial database security scanner out there. We tested it, but couldn't justify the cost. There are a butt-load of Oracle plugins for nessus. More then 7 of them are for remote shells. Nessus is a dumb scanner, if it can't see the interface to an app, it can't attack it. Likewise, if the interface requires a special client to login, it doesn't. I did a very quick look at the list of Oracle plugins, and I don't see any that check for default logins. -----Original Message----- From: Massimo [mailto:massimo.mail () quipo it] Sent: Tuesday, September 27, 2005 12:07 AM To: pen-test () securityfocus com Subject: oracle VA/PT Hi to all. Some day ago I was quite surprised to see that on a server that was d scanned with nessus and with emaze scanner that revealed no relevant security hole, there was oracle installed and active with all the default oracle user/password activated (i.e. system/manager, scott/tiger, etc). What VA tool can find default user on oracle? Is it possible to find that info with Nessus (perhaps I can't use it at its best)? Best Regards, Massimo PS I usually activate all the check on nessus and emaze. ------------------------------------------------------------------------ ------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 ------------------------------------------------------------------------ ------- ------------------------------------------------------------------------------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 -------------------------------------------------------------------------------
Current thread:
- oracle VA/PT Massimo (Sep 27)
- Re: oracle VA/PT Lukasz Szczepanski (Sep 28)
- Re: oracle VA/PT jd (Sep 29)
- <Possible follow-ups>
- RE: oracle VA/PT Josh Perrymon (Sep 28)
- RE: oracle VA/PT Gus Fritschie (Sep 29)
- RE: oracle VA/PT Josh Perrymon (Sep 28)
- RE: oracle VA/PT Michael Gargiullo (Sep 28)
- Re: oracle VA/PT Joshua Wright (Sep 29)