Главная
Study mode:
on
1
Introduction
2
Who am I
3
History
4
Launching External Procedures
5
Oracles Fix
6
Backend Bypass
7
Patches
8
Oracle vs Microsoft
9
Oracle Data Redaction
10
Why Redaction
11
How it works
12
XML query vulnerability
13
Updating a column
14
Brute force
15
Common Criteria
16
Protection Profile
17
Data is not changed
18
Is it useful
19
PCI compliance
20
Data encryption
21
How do I protect against this
22
Oracles internal processes
23
Its not rocket science
24
No documentation
25
Oracle Fusion Media Pack
Description:
Explore the vulnerabilities in Oracle's data redaction service, introduced in Oracle 12c, through this Black Hat conference talk. Learn how the service, designed to protect sensitive data like PII, can be bypassed by attackers, potentially leading to privilege escalation. Delve into the history of Oracle security issues, examine the implementation flaws, and discover multiple attack vectors that compromise the redaction feature. Understand the implications for PCI compliance and data encryption. Compare Oracle's approach to Microsoft's, and gain insights into Oracle's internal processes and documentation practices. Discover practical strategies to protect against these vulnerabilities and critically evaluate the effectiveness of Oracle's data redaction service in real-world scenarios.

Oracle Data Redaction is Broken

Black Hat
Add to list