Security:
News ToolsReg Shops |
Comments on ‘Zero-day bug hangs over Oracle database’Forget about itPublished Friday 9th November 2007 14:33 GMT
Great attitude guys!By Jason Evans
Posted Friday 9th November 2007 14:45 GMT
So with all the flack that MS got from Oracle regarding security (including Oracle's Unbreakable campaign about 6 years ago), I think it's totally outrageous that Oracle's answer to fixing a security flaw is 'Yes we have resolved the problem, but we're not releasing the fix until next year.' - yeah, that's the way to win confidence in your customers lads! So whilst admins are waiting for the fix, they will have plenty of anxious moments wondering if they are at risk from this bug. At least MS has gotten their act together and release security patches often. Even if they do still get negative opinions about their software, at least they have listened to customer needs regarding software security. NHS Spine upgrade to Oracle 10gBy Anonymous Coward
Posted Friday 9th November 2007 15:09 GMT
Apparently, according to.... http://www.e-health-insider.com/news/3176/spine_to_be_shut_for_two_day_'refresh' That link, the NHS are due to upgrade the SPINE to Oracle 10g at the end of this month. That could be fun for privacy bods! I'm not sure I want a "rushed" patch....By Rob W
Posted Friday 9th November 2007 17:59 GMT
Yes, 2 months is a long time to wait for a patch. But I'm willing to wait. Oracle has a much higher stability requirement than, say, Microsoft OS patches, or various web browsers. They have rigid patch release cycles because there are lots of steps involved in coding, checking, testing, etc. patches before they can make a release. They simply cannot hack a quick fix together in a day or two and throw it out there. And frankly, how big of a risk is this? The Oracle database servers on projects that I've run would never be exposed to external access. And to EXPLOIT this vulnerability (to install malware on the server) the attacker must already be signed into the database... aren't you basically screwed anyway if you're letting unknown users get that far? Ok...By Fraser
Posted Friday 9th November 2007 19:39 GMT
I reckon that we should start a good ol' fashioned my database is better than your database row, a la the MacOS, Windows, Linux rows. Here are my starters for ten: Oracle sucks, their security is bollox, you want to get yourself SQL Server, a modern database cheaper faster better. Or Oracle sucks, you want to get yourself DB2, runs on almost all hardware not like that sucky SQL server Or DB2? An old database for old men, who cares if it runs on Z OS. Or SQL Server? WFT? Why would you get a database that only runs on Winblows? Zero dDay Opportunities.By amanfromMars
Posted Saturday 10th November 2007 08:45 GMT
"And to EXPLOIT this vulnerability (to install malware on the server) the attacker must already be signed into the database... aren't you basically screwed anyway if you're letting unknown users get that far?" Who is saying that the users are unknown? They could be known unknowns that you didn't know you knew. And to EXPLOIT the Zero dDay Opportunities, ignore them as malware at your Peril for who would be to say that it is not palware...... which would be perfectly consistent with known unknowns having got that far. Pause....Ponder.... Promulgate Privately Pleases Parallel P.Irate* Programmers. * Pretty Irate The period for commenting on this story has finished |
|
Top 20 stories • All The Week’s Headlines • Archive • Search