|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Oracle WebDb engine brain-damagse
From: Michal Zalewski (lcamtuf
DIONE.IDS.PL)Date: Fri Dec 22 2000 - 04:46:56 CST
- Next message: Dunker, Noah: "Re: Sample SecurID Token Emulator with Token Secret Import"
- Previous message: Raptor: "Re: BS Scripts Vulnerabilities"
- In reply to: Michal Zalewski: "Re: Oracle WebDb engine brain-damagse"
- Next in thread: Kuznetsov, Vasily: "Re: Oracle WebDb engine brain-damagse"
- Reply: Michal Zalewski: "Re: Oracle WebDb engine brain-damagse"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Fri, 22 Dec 2000, Michal Zalewski wrote:
> I believe you can do at least one of these possibilities:
>
> - SELECT <pattern> INTO <sth> FROM <table> to move sensitive data
> from some private table to publicly available tables used eg. for
> direct contents rendering,
This one should work fine...
> - call WebDB output procedures to produce output (you can use full
> PL/SQL language syntax, including loops, declarations etc).
This one as well. I've just checked, no problems: you can call
owa_util.tableprint(...) and other output procedures :)
-- _______________________________________________________ Michal Zalewski [lcamtuftpi.pl] [tp.internet/security] [http://lcamtuf.na.export.pl] <=--=> bash$ :(){ :|:&};: =--=> Did you know that clones never use mirrors? <=--=
- Next message: Dunker, Noah: "Re: Sample SecurID Token Emulator with Token Secret Import"
- Previous message: Raptor: "Re: BS Scripts Vulnerabilities"
- In reply to: Michal Zalewski: "Re: Oracle WebDb engine brain-damagse"
- Next in thread: Kuznetsov, Vasily: "Re: Oracle WebDb engine brain-damagse"
- Reply: Michal Zalewski: "Re: Oracle WebDb engine brain-damagse"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]