Get a Pentest and security assessment of your IT network.

Cyber Security

Oracle Database stealth password cracking vulnerability

Oracle suffered with serious vulnerability in the authentication protocol used by some Oracle databases. This Flaw enable a remote attacker to brute-force a token provided by the server prior to authentication and determine a user’s password. The vulnerability enables an attacker to link a specific session key with a specific password hash. There are no overt signs when an outsider has targeted the weakness, and attackers aren’t required to have “man-in-the-middle” control of a network to exploit it. Oracle has no plans to fix the flaws for version 11.1 and 11.2 versions.

Source: https://thehackernews.com/2012/09/oracle-database-stealth-password.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security