Hackproofing
Oracle Application Server
(A Guide to Securing
Oracle 9)
David Litchfield(david@ngssoftware.com)
www.ngssoftware.com
NGSSoftware Insight Security Research Contents
Introduction
Oracle Architecture
Oracle Apache
PL/
SQL
Buffer Overflows
Directory Traversal
Administration
OWA_UTIL package
PL/
SQL Authentication By-pass
PL/
SQL Cross-site scripting
OracleJSP
Translation Files
JSP
SQL Poisoning
Globals.jsa
Physical Path mapping
X
SQL
X
SQLConfig.xml Access
中国网管论坛bbs.bitsCN.com
X
SQL SQL Poisoning
X
SQL Style Sheets
SOAP
SOAP Application Deployment
SOAP Configuration File
SAMPLES
Dangerous Samples
DEFAULTS
Dynamic Monitoring Services
Perl Alias
TNS LISTENER
Listener Security Issues
EXTPROC and External Procedures
Oracle Database
PL/
SQL External Procedures
Default User Logins and Passwords
Appendix A
2