Slashdot Mirror


The Week of Oracle Database Bugs

os2man writes "After the Month of Browser Bugs and the Month of Kernel Bugs, December will have a Week of Oracle Database Bugs. This project will release, every day for a week, a new 0-day bug specific to Oracle in order to show the current status of its [in]security. They are currently asking for new bugs, in order to extend the publication of new exploits a few more days."

4 of 56 comments (clear)

  1. Great by Spritzer · · Score: 4, Interesting

    Maybe they should look at security issues with Oracle's Discoverer client as well. It's pretty sad when having "@" in your password will compromise every character that follows within your password. For example, if ODB password were Sl@shd0t! and the database to connect to were BOB, at the next login the Connect field would be filled with shd0t!@BOB. Not a huge issue, but certainly a risk if multiple people with varying permissions/responsibilities in Oracle have access to a machine with Discoverer.

  2. um yeah by stoolpigeon · · Score: 5, Insightful

    without even commenting on the quality of oracle's rdbms, this statement:
    Why not the Month of Oracle Database Bugs?
    We could do the Year of Oracle Database Bugs but we think a week is enough to show how flawed Oracle software is, also we don't want to give away all our 0days:), anyways if you want to contribute send your Oracle 0days so this can be extended for another week or more.

     
    doesn't even make sense. They have enough to do a whole year but ask for people to send in more to extend it to a second week? Because they don't want to compromise their entire zero day horde? Sorry but I just can't take these people too seriously.

    --
    It's hard to believe that's how Micronians are made. Why don't we see it right now by having you both kiss one another?
  3. 0-day by Schraegstrichpunkt · · Score: 4, Funny

    That word. I do not think it means what you think it means.

  4. Next by Anonymous Coward · · Score: 5, Funny

    I presume that will be followed by 2007, "The Year of Windows Vista Bugs"?