Google blocks dangerous Oracle queries
In reaction to the
article on using Google to identify exploits on web-enabled Oracle
systems, Oliver Griffiths, an analyst for the UK Defence Academy
at Cranfield University noted that Google has shut-down some Google
searches that might be used by bad guys to hack into online Oracle
databases.
The Google search to identify sqlnet.ora files has now been
disabled by Google:
filetype:ora+sqlnet
However, the search to find people's init.ora files is still
enabled by Google:
filetype:ora init
The bestselling book “Google
Hacking for Penetration Testers”, Johnny Long’s idea has opened
many people’s eyes about the power of Google when placed in the
wrong hands.
For example, just
run this Google search below to identify dozens of web-sites
with a iSQL*Plus interface, the first-step by a hacker who is
interested in launching a buffer overflow attack on your Oracle
database.
|
|
Need an Oracle Health Check?
- Do you have
bad performance after an upgrade?
- Need to
certify that your database follows best practices?
BC Oracle performance gurus can quickly
certify every aspect of your
Oracle database and provide a complete verification that your database
is fully optimized. |

|
 |