Penetration Testing mailing list archives

Re: Oracle?


From: rajat swarup <rajats () gmail com>
Date: Tue, 6 Oct 2009 13:00:04 -0400

On Wed, Sep 23, 2009 at 5:13 PM, Xavier Mertens <xavier () pwn3d be> wrote:
I'll perform a pentest against an Oracle DB.
Anybody has a list of classic tests to be performed against a version 10 & 11 ?

This is a little dated but this could be helpful as it does give a
whole bunch of default credentials or possible things that could be
done wrong:
http://www.sans.org/score/oraclechecklist.php

HTH,
-- 
Rajat Swarup

http://rajatswarup.blogspot.com/

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: