eWeek Security Watch
Advertisement
Advertisement
November 20, 2006 4:29 PM

Coming in December: Oracle Zero-Day Flaws



oracle_logo.gif On the heels of HD Moore's Month of Browser Bugs and LMH's Month of Kernel Bugs, a database security research expert plans to start a new project dedicated to releasing zero-day flaws in Oracle database server and application products...

oracle_ad.jpg

Cesar Cerrudo, founder and CEO of Argeniss Information Security, is setting aside a week in December for the WoODB (Week of Oracle Database Bugs) to expose what he describes as Oracle's failure to adequately secure its products.

"We want to show the current state of Oracle software (in)security and demonstrate Oracle isn't getting any better at securing its products (you already know the history: two years or more to fix a bug, not fixing bugs, failing to fix bugs, lying about security efforts, etc, etc, etc.)," Cerrudo said in a note announcing the project.

The Argentinian hacker has stockpiled zero-day vulnerabilities for all database software vendors but decided to concentrate on Oracle because it is the "#1 star" when it comes to unpatched vulnerabilities and a laissez-faire attitude towards security.

"We could do the Year of Oracle database bugs but we think a week is enough to show how flawed Oracle software is," Cerrudo added.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/9729

Post a Comment

 
 
RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise