Basic networking knowledge is required and a familiarization with database concepts would be beneficial. Experience or knowledge of specific database solutions is desirable, though not essential in order to complete the course satisfactorily.
Participants are requested to bring their own laptops with and Oracle client installed.
Black Hat DC Training 2008
Westin Washington DC City Center • Feburary 18-19
Breakable: Secure Your Oracle Servers By Breaking Into Them
David Litchfield, NGS Software & Mark Litchfield, NGS Software
A new course designed and taught by world renown security vulnerability researcher David Litchfield.
Overview:
Never has the need for understanding Oracle database security been so great as it is today as the boundaries between networks become less defined and web applications provide direct inroads through any firewalls and into the backend. This course will teach you how to hack into Oracle database servers; only by truly grasping the mechanics of attacks can a complete and effective defense be built. We will cover all aspects of breaking into Oracle database and application servers covering such topics as
PLSQL Injection
Abusing Triggers
Defeating Virtual Private Databases
Defeating Oracle Label Security
Indirect Privilege Escalation
Buffer Overflows
Local Attacks
Hacking the Authentication Process
Hacking the TNS Listener
Hacking the XML Database
Hacking Oracle Application Server
Hacking an EAL4 Certified Database
and Much, Much More
Prerequisites
A prior knowledge of Oracle would be useful but not necessary.
Who Should Take the Course
Anyone interested in Oracle Database Security
Trainer:
David Litchfield
Founder and Chief Scientist, NGS Software
David Litchfield is the founder and Chief Research Scientist of NGSSoftware Ltd, a U.K. based security solutions provider. He is the co-author of "The Database Hacker's Handbook", "The Shellcoder's Handbook", "SQL Server Security" and "Special Ops". He has lectured both the National Security Agency in the U.S. and G.C.H.Q. in the U.K. on emerging threats and information assurance.
He is a regular speaker at the Black Hat Security Briefings and has also presented at Microsoft Bluehat and Microsoft TechEd. Previously he was the Director of Security Architecture of @stake, since accquired by Symantec and the founder and Managing Director of Cerberus Information Security Ltd, which was accquired by @stake in July 2000. At NGSSoftware, as well as conducting research into new computer vulnerability, David has designed and help develop NGSSQuirreL, a powerful tool for advanced database vulnerability and risk assessment.
Trainer:
Mark Litchfield
Director, NGS Research
Mark Litchfield was jointly voted the 'Best Bug Hunter' for computer security vulnerability discovery (with his brother David) and is one of the six founding members of NGSSoftware.
With his vast experience of network and application penetration testing, Mark has discovered and published over 200 major security vulnerabilities in many different products, including most notably Apache, Microsoft Internet Information Server, Oracle database server and Microsoft SQL Server. In every case where Mark has found vulnerabilities, he has worked closely with the affected vendors in order to develop solutions that will protect their customers. Mark is also currently involved with the business development side of NGS.