"Hundreds of Oracle Products"

In the Oracle pre-release announcement for the April 2008 Critical Patch Update, one line in particular did catch my attention. I know Oracle has purchased many companies in the past few years.  So how many products does Oracle have?  Well, the CPU pre-release announcement states that --

COLLABORATE 08 Presentations

For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG), Independent Oracle Users Group (IOUG), and Quest have teamed together to host a user-driven event with exceptional content.  COLLABORATE 08 is next week, Sunday, April 13 through Thursday, April 17 in Denver.  This year there will be over 500 technical sessions covering virtually every Oracle product. 

Oracle Critical Patch Updates - Types of Fixes in Database Patches

An issue in applying Oracle Critical Patch Update (CPU) database security patches has been that the patches may include non-security related fixes.  The list of bugs fixed in the database patch readme is cryptic at best and it can be difficult to to determine the true impact of a specific CPU patch.  By including non-security related fixes in the CPU patch reduces the confidence that the patch will not break something.

Oracle Exploits

Since several new Oracle exploits were published this week, I thought it would be a good time to provide some background on exploits.

OAUG eLearning: Oracle Critical Patch Update January 2008

This quarters Oracle Critical Patch Update (CPU) was released on Tuesday, January 15th.   In order to provide a better understanding of the CPU, I will be presenting an Oracle Applications Users Group (OAUG) eLearning session on Thursday.  The presentation will focus on the impact to Oracle E-Business Suite environments.

Thursday, January 17 at 9:00 am and 5:00 pm U.S. Eastern Time

Oracle Critical Patch Update - January 2008 - E-Business Suite Impact

Oracle released the thirteenth Critical Patch Update (CPU) today.  This quarter is the same as the previous twelve with many patches and long hours in order to get all the security patches applied in a timely manner.  17 of the 27 vulnerabilities fixed impact Oracle E-Business Suite 11i.  Fortunately like the last few quarters, this quarter there are no new Oracle Application Server or Developer 6i patches required for the Oracle E-Business Suite 11i.

Critical Patch Update January 2008 E-Mail Reminder

As part of the Oracle quarterly Critical Patch Update (CPU) process, a new reminder e-mail of the upcoming CPU is being sent to all individuals who signed up for e-mail notifications on the CPU web page.  This e-mail is only a reminder that the next CPU will be released on January 15, 2008 (sometime after noon Pacific Time).

Oracle Employees Really Do Read This Blog

From the Integrigy servers statistics, I have known that we get hundreds of visits a day from the Oracle proxy and cache servers.  Many days collectively the Oracle domains (.com, .uk, etc.) are number one.  The vast majority of the hits are on blog, RSS feeds, and our whitepapers.  But I have not known how Oracle actually uses this information internally.  Well, now I know someone is at least reading our comments and recommendations.

Connect It and The Hackers Will Come

When clients are deploying an unpublished supplier or customer application to the Internet for the first, they are always amazed at the sheer number of random attacks.  Granted many of these are looking for PHP pages or some other long ago patched vulnerability.  The question that always arises is "How did they find the server so quickly?"  Well, the hackers are just searching blocks of addresses on a continual basis.

Hashing Credit Card Numbers: Revisited

This past March, I published a white paper looking at how some applications hash credit card numbers and how vulnerable these hashes are to brute forcing.  I developed a proof of concept to roughly estimate the timings (about 2 million hashes per second).  Looking ahead, I estimated with additional optimization, multi-threading, and faster processors probably 50 million hashes per second is achievable.