Penetration Testing mailing list archives
Re: Oracle?
From: rajat swarup <rajats () gmail com>
Date: Tue, 6 Oct 2009 13:00:04 -0400
On Wed, Sep 23, 2009 at 5:13 PM, Xavier Mertens <xavier () pwn3d be> wrote:
I'll perform a pentest against an Oracle DB. Anybody has a list of classic tests to be performed against a version 10 & 11 ?
This is a little dated but this could be helpful as it does give a whole bunch of default credentials or possible things that could be done wrong: http://www.sans.org/score/oraclechecklist.php HTH, -- Rajat Swarup http://rajatswarup.blogspot.com/ ------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------
Current thread:
- Re: Oracle? rajat swarup (Oct 06)