Главная
Study mode:
on
1
Intro
2
Who Am I?
3
eBusiness Suite Overview
4
eBusiness Suite components
5
eBusiness Suite Vulnerabilities
6
Some 11.5 Issues
7
trusted.conf
8
PL/SQL Gateway
9
HR UTIL DISP WEB
10
display_fatal errors
11
Attack Sequence
12
ORACLESSWA
13
RUNFUNCTION
14
Arbitrary SQL
15
Some 12.x Issues
16
Many ways to skin a cat
17
JSP forwards
18
Auxiliary Inject Functions 1/2
19
Executing SQL as SYS
20
SQL Injection in SYSTEM.AD_APPS PRIVATE
21
Securing 12.x and 11.5
22
Specific to Securing 11.5
23
Securing eBusiness Suite
24
Questions?
Description:
Explore a comprehensive security analysis of Oracle's eBusiness Suite in this Black Hat conference talk. Delve into the vulnerabilities discovered by David Litchfield, including unauthenticated remote code execution flaws, SQL injection vulnerabilities, and Cross Site Scripting bugs. Learn about the weaknesses in both 11.5 and 12.x versions, with demonstrations of exploit techniques. Discover methods to secure eBusiness Suite implementations against these attacks, covering topics such as trusted.conf, PL/SQL Gateway, HR UTIL DISP WEB, and SYSTEM.AD_APPS PRIVATE. Gain insights into protecting large corporate systems using this widely-deployed product, and participate in a Q&A session to address specific security concerns.

Hackproofing Oracle EBusiness Suite

Black Hat
Add to list
0:00 / 0:00