Re: Testing ORACLE application

From: Victor Stinner (victor.stinner@haypocalc.com)
Date: Thu Jan 03 2008 - 14:55:20 EST


Hi,

On Wednesday 02 January 2008 11:01:33 ahgaber_rehan@yahoo.com wrote:
> I am in process of testing some web based oracle applications, I need to
> know what has to be tested and recommended tools I can use.
>
> Simply ( pen testing guide for ORACLE application)

A friend pointed by to Inguma, fuzzer which targets especially Oracle:
   http://inguma.sourceforge.net/

See for example this video:
   http://inguma.sourceforge.net/text/inguma_text.html

We can see commands to: scan port, guess Oracle version, guess SID, bruteforce
password, ...

Victor
http://fusil.hachoir.org/ -- new release (0.7) of the fuzzer today

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:18 EDT