OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Ron Cohen (secrony.clara.net)
Date: Sat Aug 04 2001 - 20:04:09 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    BY removing the suid bit from oracle, ay client connection originated
    from non-oracle user will cause oracle to revert to tcp connection
    instead of pipe. be prepared to a considerable performance degrading
    if you choose this tactic.

            _rony

    -----Original Message-----
    From: paskplazasite.com [mailto:paskplazasite.com]
    Sent: 02 August 2001 08:57
    To: bugtraqsecurityfocus.com; oracle-lfaticity.com
    Subject: vulnerability in oracle binary in Oracle 8.0.5 - 8.1.6

       Title: Vulnerability in oracle binary in Oracle 8.0.5

     ....

    SOLUTION:
        Chmod -s ;-)))).

    STATUS:
        Vendor was contacted .

    ----------------
    This vulnerability was researched by:
    Juan Manuel Pascual Escriba paskplazasite.com

    ---
    Outgoing mail is certified Virus Free.
    Checked by AVG anti-virus system (http://www.grisoft.com).
    Version: 6.0.265 / Virus Database: 137 - Release Date: 18/07/2001