The Week of Oracle Database Bugs
os2man writes "After the Month of Browser Bugs and the Month of Kernel Bugs, December will have a Week of Oracle Database Bugs. This project will release, every day for a week, a new 0-day bug specific to Oracle in order to show the current status of its [in]security. They are currently asking for new bugs, in order to extend the publication of new exploits a few more days."
without even commenting on the quality of oracle's rdbms, this statement:
Why not the Month of Oracle Database Bugs?
We could do the Year of Oracle Database Bugs but we think a week is enough to show how flawed Oracle software is, also we don't want to give away all our 0days:), anyways if you want to contribute send your Oracle 0days so this can be extended for another week or more.
doesn't even make sense. They have enough to do a whole year but ask for people to send in more to extend it to a second week? Because they don't want to compromise their entire zero day horde? Sorry but I just can't take these people too seriously.
It's hard to believe that's how Micronians are made. Why don't we see it right now by having you both kiss one another?
but why do they need help to extend it a week if they have enough to last a year?
It's hard to believe that's how Micronians are made. Why don't we see it right now by having you both kiss one another?
by exposing 0-day bugs other than helping bad hackers but I would love to see someone poke holes in MS SQL server.
/ 07/sql-server-2005-1-year-and-not-yet-counting.asp x
Its been 1 year with no known exploits in SQL Server 2005 (zero in the product lifetime)
http://blogs.technet.com/security/archive/2006/11
They say A) they have enough bugs (erherm, not exploits) to last a year B) they also say (I won't even speculate on the quality of the comment) "we don't want to give away all our 0days".
So whatever. They had a weeks worth of exploits and they'd like some other people to pony up so they can make it two while holding on to some super-secret exploits. 7337!
Anyway, slamming on Oracle seems a little silly. Its software, there will be problems.
Quack, quack.