Penetration Testing mailing list archives

Re: Testing ORACLE application


From: Victor Stinner <victor.stinner () haypocalc com>
Date: Thu, 3 Jan 2008 20:55:20 +0100

Hi,

On Wednesday 02 January 2008 11:01:33 ahgaber_rehan () yahoo com wrote:
I am in process of testing some web based oracle applications, I need to
know what has to be tested and recommended tools I can use.

Simply ( pen testing guide for ORACLE application)

A friend pointed by to Inguma, fuzzer which targets especially Oracle:
   http://inguma.sourceforge.net/

See for example this video:
   http://inguma.sourceforge.net/text/inguma_text.html

We can see commands to: scan port, guess Oracle version, guess SID, bruteforce 
password, ...

Victor
http://fusil.hachoir.org/ -- new release (0.7) of the fuzzer today

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: