RE: Testing ORACLE application

From: Syed Khaden (syed@secure-bytes.com)
Date: Tue Jan 08 2008 - 08:10:12 EST


try this
http://www.secure-bytes.com/FreeToolsSetup/OraTNSCheck.exe

-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com] On
Behalf Of Victor Stinner
Sent: Friday, January 04, 2008 12:55 AM
To: pen-test@securityfocus.com
Subject: Re: Testing ORACLE application

Hi,

On Wednesday 02 January 2008 11:01:33 ahgaber_rehan@yahoo.com wrote:
> I am in process of testing some web based oracle applications, I need
> to know what has to be tested and recommended tools I can use.
>
> Simply ( pen testing guide for ORACLE application)

A friend pointed by to Inguma, fuzzer which targets especially Oracle:
   http://inguma.sourceforge.net/

See for example this video:
   http://inguma.sourceforge.net/text/inguma_text.html

We can see commands to: scan port, guess Oracle version, guess SID,
bruteforce password, ...

Victor
http://fusil.hachoir.org/ -- new release (0.7) of the fuzzer today

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:19 EDT