Penetration Testing mailing list archives

RE: oracle VA/PT


From: "Gus Fritschie" <gfritschie () hotmail com>
Date: Wed, 28 Sep 2005 13:02:42 -0400

OAT is another good one for Oracle checks (www.cqure.net)


From: "Josh Perrymon" <perrymonj () networkarmor com>
To: "Massimo" <massimo.mail () quipo it>, <pen-test () securityfocus com>
Subject: RE: oracle VA/PT
Date: Wed, 28 Sep 2005 06:02:43 -0500

Sorry,

Got my tools mixed up. Absinthe is for SQL injection-

MetaCoretex will do the Oracle checks.

jP

-----Original Message-----
From: Massimo [mailto:massimo.mail () quipo it]
Sent: Tuesday, September 27, 2005 12:07 AM
To: pen-test () securityfocus com
Subject: oracle VA/PT

Hi to all.

Some day ago I was quite surprised to see that on a server that was
scanned with nessus and with emaze scanner that revealed no relevant
security hole, there was oracle installed and active with all the
default oracle user/password activated (i.e. system/manager,
scott/tiger, etc).

What VA tool can find default user on oracle? Is it possible to find
that info with Nessus (perhaps I can't use it at its best)?

Best Regards,
                Massimo
PS
I usually activate all the check on nessus and emaze.

------------------------------------------------------------------------
------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on
your
website. Up to 75% of cyber attacks are launched on shopping carts,
forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers
are
futile against web application hacking. Check your website for
vulnerabilities
to SQL injection, Cross site scripting and other web attacks before
hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
------------------------------------------------------------------------
-------





------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------




------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: