Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Oracle and setting the record straight |
|---|---|
| Date: | Fri, 22 Jul 2005 20:14:43 +0100 |
Hey all,
I don't know whether this helps serve any purpose or not, other than the vent some of my own frustrations; however...
In the wake of the release of Alex Kornbrust's details on some Oracle flaws there has been some discussion in various places about when I supposedly did the same thing last year at Blackhat - i.e. release information on Oracle bugs in the absence of a vendor supplied patch.
For the record, I did _not_ do this.
So, setting the record straight: I was due to present a talk that centered around a batch of Oracle vulnerabilities at Blackhat last year. I gave Oracle a heads up and explained that I intended to do so and questioned whether the patches would be ready. On the day of the talk I was informed by Oracle that the patches were not ready and so when I got up on the stage I proceeeded to tell everyone exactly why I could no longer do the talk. i.e. I can't do the talk because Oracle failed to patch the problems I was going to talk about.
I did not discuss in any form or fashion the actual bugs.
cheers, Adam -- Adam Laurie Tel: +44 (0) 20 7605 7000 The Bunker Secure Hosting Ltd. Fax: +44 (0) 20 7605 7099 Shepherds Building http://www.thebunker.net Rockley Road London W14 0DA mailto:adam@thebunker.net UNITED KINGDOM PGP key on keyservers
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | eBay phishing - phishers are getting better, John Gateley |
|---|---|
| Next by Date: | RE: Peter Gutmann data deletion theaory?, Tiago Halm |
| Previous by Thread: | Oracle and setting the record straight, David Litchfield |
| Next by Thread: | MDKSA-2005:122 - Updated kdelibs packages fix vulnerability in kate and kwrite, Mandriva Security Team |
| Indexes: | [Date] [Thread] [Top] [All Lists] |