| Date |
Type |
Title |
Author |
Event |
| January 08, 2012 |
Slides |
Oracle Rootkits 2.0: The Next Generation
|
Alexander Kornbrust
|
Black Hat USA 2006 |
| January 06, 2012 |
Slides |
How to Unwrap Oracle PL/SQL
|
Pete Finnigan
|
Black Hat USA 2006 |
| December 24, 2011 |
Slides |
Demystifying MS SQL Server & Oracle Database Server Security
|
Cesar Cerrudo
|
Black Hat USA 2005 |
| December 19, 2011 |
Slides |
Circumvent Oracle’s Database Encryption and Reverse Engineering of Oracle Key Management Algorithms
|
Alexander Kornbrust
|
Black Hat USA 2005 |
| December 18, 2011 |
Slides |
Advanced SQL Injection in Oracle Databases
|
Esteban Martínez Fayó
|
Black Hat USA 2005 |
| December 11, 2011 |
Slides |
Oracle PL/SQL Injection
|
David Litchfield
|
Black Hat EU 2004 |
| November 26, 2011 |
Audio |
Oracle PL/SQL Injection
|
David Litchfield
|
Black Hat Asia 2004 |
| November 26, 2011 |
Slides |
Oracle PL/SQL Injection
|
David Litchfield
|
Black Hat Asia 2004 |
| November 25, 2011 |
Slides |
Oracle Vulnerabilities
|
David Litchfield
Sherief Hammad
|
Black Hat Windows Security 2002 |
| October 16, 2011 |
Slides |
All New Oracle Ø-Day: Attacking and Defending Oracle
|
David Litchfield
|
Black Hat EU 2003 |
| September 22, 2011 |
Paper |
Hacking Oracle From Web Apps
|
Sumit Siddharth
|
Black Hat USA 2010 |
| September 09, 2011 |
Paper |
Hacking and protecting Oracle Database Vault
|
Esteban Martínez Fayó
|
Black Hat USA 2010 |
| September 09, 2011 |
Slides |
Hacking and protecting Oracle Database Vault
|
Esteban Martínez Fayó
|
Black Hat USA 2010 |
| July 30, 2011 |
Paper |
Advanced Oracle Attack Techniques
|
David Litchfield
|
Black Hat DC 2007 |
| July 30, 2011 |
Slides |
Advanced Oracle Attack Techniques
|
David Litchfield
|
Black Hat DC 2007 |
| July 28, 2011 |
Paper |
Practical 10 Minute Security Audit: The Oracle Case
|
Cesar Cerrudo
|
Black Hat DC 2007 |
| July 28, 2011 |
Slides |
Practical 10 Minute Security Audit: The Oracle Case
|
Cesar Cerrudo
|
Black Hat DC 2007 |
| March 26, 2011 |
Audio |
Hacking Oracle From Web Apps
|
Sumit Siddharth
|
DEFCON 18 |
| March 26, 2011 |
Slides |
Hacking Oracle From Web Apps
|
Sumit Siddharth
|
DEFCON 18 |
| March 26, 2011 |
Video |
Hacking Oracle From Web Apps
|
Sumit Siddharth
|
DEFCON 18 |
| February 06, 2011 |
Video |
Hacking and Protecting Oracle Database Vault
|
Esteban Martínez Fayó
|
DEFCON 18 |
| February 06, 2011 |
Slides |
Hacking and Protecting Oracle Database Vault
|
Esteban Martínez Fayó
|
DEFCON 18 |
| February 06, 2011 |
Audio |
Hacking and Protecting Oracle Database Vault
|
Esteban Martínez Fayó
|
DEFCON 18 |
| August 16, 2010 |
Video |
The Forensic Investigation of a Compromised Oracle Database Server
|
David Litchfield
|
Black Hat DC 2009 |
| August 15, 2010 |
Audio |
The Forensic Investigation of a Compromised Oracle Database Server
|
David Litchfield
|
Black Hat DC 2009 |
| June 20, 2010 |
Paper |
Oracle, Interrupted: Stealing Sessions and Credentials
|
Wendel Guglielmetti Henrique
Steve Ocepek
|
Black Hat EU 2010 |
| June 20, 2010 |
Slides |
Oracle, Interrupted: Stealing Sessions and Credentials
|
Wendel Guglielmetti Henrique
Steve Ocepek
|
Black Hat EU 2010 |
| April 28, 2010 |
Video |
The Making of the second SQL injection Worm
|
Sumit Siddharth
|
DEFCON 17 |
| April 28, 2010 |
Slides |
The Making of the second SQL injection Worm
|
Sumit Siddharth
|
DEFCON 17 |
| April 28, 2010 |
Audio |
The Making of the second SQL injection Worm
|
Sumit Siddharth
|
DEFCON 17 |
| March 15, 2010 |
Audio |
Breaking the "Unbreakable" Oracle with Metasploit
|
Chris Gates
Mario Ceballos
|
DEFCON 17 |
| March 15, 2010 |
Slides |
Breaking the "Unbreakable" Oracle with Metasploit
|
Chris Gates
Mario Ceballos
|
DEFCON 17 |
| March 15, 2010 |
Paper |
Breaking the "Unbreakable" Oracle with Metasploit
|
Chris Gates
Mario Ceballos
|
DEFCON 17 |
| March 15, 2010 |
Video |
Breaking the "Unbreakable" Oracle with Metasploit
|
Chris Gates
Mario Ceballos
|
DEFCON 17 |
| January 05, 2010 |
Video |
Oracle Rootkits 2.0
|
Alexander Kornbrust
|
DEFCON 14 |
| January 05, 2010 |
Audio |
Oracle Rootkits 2.0
|
Alexander Kornbrust
|
DEFCON 14 |
| September 06, 2009 |
Slides |
Breaking the "Unbreakable" Oracle with Metasploit
|
Chris Gates
|
Black Hat USA 2009 |
| September 06, 2009 |
Paper |
Breaking the "Unbreakable" Oracle with Metasploit
|
Chris Gates
|
Black Hat USA 2009 |
| June 28, 2009 |
Slides |
Oracle SQL Injection in Webapps
|
Alexander Kornbrust
|
Confidence 2009 Krakow |
| October 17, 2008 |
Paper |
How to write injection-proof PL/SQL
|
Oracle
|
|
| May 03, 2008 |
Paper |
Lateral SQL Injection: A new Class of Vulnerability in Oracle
|
David Litchfield
|
|
| January 05, 2008 |
Paper |
Exploiting And Protecting Oracle
|
|
|
| January 05, 2008 |
Paper |
Extracting Clear Text Passwords from the SGA
|
|
|
| January 05, 2008 |
Paper |
Oracle Default User and Password List
|
|
|
| January 05, 2008 |
Paper |
Issues with the initialisation parameter fixed date
|
|
|
| January 05, 2008 |
Paper |
Have your objects been tampered with ?
|
|
|
| January 05, 2008 |
Paper |
Some thoughts on Oracle Passwords
|
|
|
| December 30, 2007 |
Paper |
Establish security policy with Oracle virtual private database
|
Donald Burleson
|
|
| December 30, 2007 |
Paper |
Oracle Row Level Security: Part 2
|
Pete Finnigan
|
|
| December 30, 2007 |
Paper |
Oracle Row Level Security: Part 1
|
Pete Finnigan
|
|
| December 30, 2007 |
Paper |
Fine Grained Access Control
|
Tom Kyte
|
|
| December 30, 2007 |
Paper |
Oracle Virtual Private
|
Oracle
|
|
| December 30, 2007 |
Paper |
Keeping Information Private with VPD
|
Arup Nanda
|
|
| December 30, 2007 |
Paper |
Securing Oracle Applications
|
Stephen Kost
|
|
| December 30, 2007 |
Paper |
Securing Oracle9iAS 1.0.2.x
|
Stephen Comstock
|
|
| December 30, 2007 |
Paper |
Oracle Database Listener Security Guide
|
Stephen Kost
|
|
| December 30, 2007 |
Paper |
Oracle Database Checklist
|
Pete Finnigan
|
|
| December 30, 2007 |
Paper |
How to Write an Oracle Security Plan
|
Marlene Theriault
|
|
| December 30, 2007 |
Paper |
Oracle Database Security Checklist
|
Oracle
|
|
| December 30, 2007 |
Paper |
Oracle Database 10g Security
|
Oracle
|
|
| December 30, 2007 |
Paper |
Securing PL/SQL Applications with DBMS_ASSERT
|
David Litchfield
|
|
| December 30, 2007 |
Paper |
Guide to the secure configuration and administration of Oracle 9i
|
NSA
|
|
| December 30, 2007 |
Paper |
Spoofing Oracle Session Information
|
Stephen Kost
|
|
| December 30, 2007 |
Paper |
Analysis of the Oracle Oct 2006 CPU
|
David Litchfield
|
|
| December 30, 2007 |
Paper |
Project Lockdown
|
Arup Nanda
|
|
| December 30, 2007 |
Paper |
Exploiting and Protecting Oracle
|
Pete Finnigan
|
|
| December 30, 2007 |
Paper |
Hack-proofing Oracle Databases
|
Aaron Newman
|
|
| December 30, 2007 |
Paper |
Cursor Snarfing - A New Class of Attack in Oracle
|
David Litchfield
|
|
| December 30, 2007 |
Paper |
Hack Proofing Oracle Application Server
|
David Litchfield
|
|
| December 30, 2007 |
Paper |
Cursor Injection - A New Method for Exploiting PL/SQL Injection and Potential Defences
|
David Litchfield
|
|
| December 30, 2007 |
Slides |
In-memory Backdoors in Oracle
|
David Litchfield
|
|
| December 30, 2007 |
Slides |
Oracle Forensics: Collecting Evidence After an Attack
|
Aaron Newman
|
|
| December 30, 2007 |
Paper |
Oracle Database Forensics using Logminer
|
Paul Wright
|
|
| December 30, 2007 |
Paper |
Oracle Forensics in a Nutshell
|
Paul Wright
|
|
| December 29, 2007 |
Paper |
Oracle Forensics Part 1: Dissecting the Redo Logs
|
David Litchfield
|
|
| December 29, 2007 |
Paper |
Oracle Forensics Part 2: Locating Dropped Objects
|
David Litchfield
|
|
| December 29, 2007 |
Paper |
Oracle Forensics Part 4: Live Response
|
David Litchfield
|
|
| December 29, 2007 |
Paper |
Oracle Forensics Part 3: Isolating Evidence of Attacks Against the Authentication Mechanism
|
David Litchfield
|
|
| December 29, 2007 |
Paper |
Oracle Forensics Part 5: Finding Evidence of Data Theft in the Absence of Auditing
|
David Litchfield
|
|
| December 29, 2007 |
Paper |
Oracle Forensics Part 6: Examining Undo Segments, Flashback and the Oracle Recycle Bin
|
David Litchfield
|
|
| December 29, 2007 |
Slides |
Oracle Forensics
|
Pete Finnigan
Aaron Newman
|
|