Oracle: not quite so unbreakable


Recommended Posts

It seems as tho Orcale's claim to have "unbreakable" software is, well, a lie.

You may have seen Oracle's ad on TV:

"Oracle9i. Unbreakable. Can't break it. Can't break in."

I know of quite a few tech mags that advertise putting Exchange on Orcale in order to make it "unbreakable".

According to one UK security expert, they're full of it.

http://www.securityfocus.com/news/309

Breakable

A U.K. security expert is preparing to unveil a trove of serious vulnerabilities in Oracle's database products. Can the company redefine 'unbreakable' in time?

By Kevin Poulsen

Jan 16 2002 1:26AM PT

An Oracle advertisement emailed last week to InfoWorld subscribers typifies the software company's newest marketing campaign. It begins with the unsettling assertion that annual computer security incidents have increased ten-fold since 1997, then lists the ways that the company's database products can defend the reader against hackers. The ad ends with a now-familiar claim, "Oracle9i. Unbreakable. Can't break it. Can't break in."

That simple bold message of invulnerability has grown into something of an IT cultural touchstone since Oracle CEO Larry Ellison unveiled the campaign at Comdex last November. The "unbreakable" claim is writ large on billboards, sent out in email ads, printed in the glossy pages of magazines, and displayed on Web banners. Type "unbreakable" into Google and a sponsored link to Oracle is likely to pop up on top. The campaign seems to touch a chord, implicitly promising safety from unseen attackers, and certainty in an uncertain time.

If the marketing message suffers from one flaw, it is this: It isn't exactly true. In December, U.K. security researcher David Litchfield revealed that a common programming error -- a buffer overflow -- was present in Oracle's application server, potentially allowing hackers to gain remote access to the system over the Internet. PenTest Limited and eEye Digital Security followed up with advisories of their own on less severe holes. Fixes are available for all three bugs on the Oracle Web site, but the damage to the company's "unbreakable" messaging isn't as easily patched.

'When they say their software is unbreakable, they're lying.'

-- Bruce Schneier

"If to them 'unbreakable' doesn't even mean they eliminate buffer overflows, how can it possibly mean they've secured the hard stuff?," says Bruce Schneier, founder and CTO of Counterpane Internet Security. "Fixing buffer overflows is the price of admission."

Making matters worse for Oracle, it turns out that those holes were little more than a prelude to a suite of at least seven vulnerabilities currently in the company's patch pipeline -- all of them discovered by Litchfield last fall. Assuming fixes are available in time, Litchfield plans to present the holes at a security conference in early February, including details of serious bugs that allow attackers to both "break it" and "break in."

"They range from buffer overflows, to something in the way Oracle communicates with different components," says Litchfield, lead designer and developer at NGSSoftware. "We can actually interject ourselves in between that communications process and run commands as SYSTEM on Windows NT or 2000. If it's running on a Unix system, we can run commands as the Oracle user remotely... So it's obviously very serious."

While Oracle's vulnerabilities are no greater in number or severity than those found in other major software products, some experts charge that the steady stream of security holes transforms "unbreakable" from a harmless marketing gimmick into a potentially dangerous misstatement.

"The more people out there saying they have an unbreakable product, it gives customers a false sense of security," says David Dittrich, senior security engineer at the University of Washington. "I'd rather they boast about having a good programming team, or a good auditing process."

'Obvious' Hole in Database Server

"We all know it's breakable," says Tim Mullen, CIO of AnchorIS.Com, and a columnist for SecurityFocus. Mullen broke the news of the latest batch of Oracle holes in a recent column critical of the company. "The only people who don't know it's breakable, apparently, are Ellison, and the reportedly high numbers of businesses that have now chosen to purchase the product as a result of the 'Unbreakable' campaign," Mullen says.

But Oracle chief security officer Mary Ann Davidson says the criticism is unfair. In an emailed response to Mullen's commentary, Davidson wrote that Oracle is giving the holes reported by Litchfield the "highest priority," but suggested that everything depends on what your definition of "unbreakable" is.

Rather than representing a literal claim that Oracle's products are impregnable, the campaign "speaks to" fourteen independent security evaluations that Oracle's database server passed, Davidson wrote, and "represents Oracle's commitment to a secure product lifecycle for our entire product suite."

"We believe the market effect of the 'Unbreakable' campaign raises the security bar and therefore improves security overall, both in forcing us to live up to the statement, and forcing others in the industry to begin to do the same," wrote Davidson. "If our security today is imperfect but better than the competition, and if customers make a buying decision based on that criteria, than in the long term you will see all products in the market improve."

A company spokesperson declined to discuss any particular security holes, or how they can be reconciled with Oracle's "Unbreakable" and "Can't break in" claims. But in a written statement, the company emphasized that Oracle responds quickly to close newly-discovered vulnerabilities -- an assessment with which Litchfield agrees.

"The Oracle database server itself runs on some sixty odd different operating systems," says Litchfield. "They have to test each different operating system. A couple of months is a speedy response."

Litchfield discovered the slew of vulnerabilities while developing NGSSoftware's Oracle security scanner, planned for release next month. He issued an advisory on one of the holes in December, after Oracle made a fix available. Details on the other, more serious holes remain a closely held secret pending more patches, which Litchfield hopes to see the company deliver in time for a presentation he has planned for the Black Hat Windows Security conference in New Orleans on February 7th.

He says he's not aware of any of the holes being actively exploited by hackers, but offers that one of the more serious vulnerabilities has been in every revision of Oracle's database server since at least Oracle 8, which was released in 1999. "When this information goes public, you'll go, 'Oh my God, that's so obvious, why didn't anybody think of that before?,'" says Litchfield.

Litchfield says he isn't bothered by Oracle's "Unbreakable" claim -- he's satisfied with Davidson's explanation that the campaign is really just meant to underscore the software's lineup of security certifications. But Schneier, and other experts, say that security is too serious to be made the stuff of exaggerated marketing claims.

"I don't like it when marketing jargon takes over reality," says Schneier. "The word 'unbreakable' has a meaning, in English. When they say their software is unbreakable, they're lying."

Link to comment
https://www.neowin.net/forum/topic/12013-oracle-not-quite-so-unbreakable/
Share on other sites

saw some news on tweakers.net (dutch site) a while back.

David Litchfield from NGS Software showed how to get admin rights, via buffer overflows or something like that, and crashed a oracle system in 10 minutes.

I believe it was two weeks after the "big" speech from that oracle big shot...

Yep.

And he's probably going to talk all about it early next month at a security conference... won't that be fun for Oracle.

Note to CEO's: saying something can't be done is like painting a target on your head. Don't do it unless you really, really want to see what can happen...

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The memory and nvme can be swapped and upgraded with standard parts. But the GPU cannot, which is the weakest part of the box. It's a dead product at these prices.
    • Sounds like the debloated build you are running is missing some components that the Photos app and Snipping Tool rely on.
    • Apparently, Microsoft doesn't use water in their taps, washrooms or clean their facility. /sarc
    • Wow, throwback.  VERY VERY briefly - but realised that it wasn't the language I needed for the tasks I was taking on.
    • Apple and Tesla trade secrets reportedly exposed following a Tata Electronics cyberattack by Hamid Ganji Image via Depositphotos.com Tata Electronics has confirmed that it detected a cybersecurity incident in some of its systems. The Indian company is a manufacturing partner of both Apple and Tesla, and the incident may have exposed some trade secrets belonging to the two American companies. The World Leaks ransomware group is said to be behind the attack, and it has reportedly posted up to 200,000 files on the dark web, including component designs and specification documents related to Apple and Tesla products. Tata Electronics told Reuters that its response protocols were deployed immediately and that the “incident has had no impact on our operations across businesses, which remain unaffected.” The ransomware group reportedly sent a ransom demand to Tata Electronics, while Apple has launched an investigation into the incident. World Leaks claims it stole more than 200,000 files totaling over 630GB from Tata Electronics. Some database files on the ransomware group’s website are titled "com.apple.factorydata," which could refer to Apple’s iPhone production operations in India. Moreover, some documents reportedly contain material specifications and quality inspection standards for iPhone circuit board components. However, Apple is not the only affected company. A folder found in the World Leaks database is titled "NV36 Chargeport Controller - North America," which may refer to Tesla Model Y components. Additionally, other files in the database reportedly contain drawings related to Tesla’s Project Highland, the internal codename for the EV maker’s updated Model 3 sedan. To support the authenticity of the stolen files, World Leaks has published documents containing footers that read: "This document contains proprietary and confidential information of Apple Inc." and "information contained herein is deemed confidential, proprietary, and a trade secret of Tesla Inc." Cybersecurity researcher Rajshekhar Rajaharia told Reuters that the database also contains emails, event logs spanning several years, and passport copies of employees, including foreign nationals. Both Tesla and Apple have declined to comment on the scale of the incident.
  • Recent Achievements

    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
    • Dedicated
      tuben earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      478
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      96
    4. 4
      Michael Scrip
      91
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!