Black Hat: Litchfield's Oracle talk nixed
Thu, 2008-08-07 00:47

As my colleague Brian Krebs has noted, often the talks that don't happen are more interesting than the ones that do.

Apple certainly didn't earn any PR points in the security community, by scrapping a talk that its engineers were set to give on the company's security response team. Now an Oracle talk by David Litchfield (he's famous as the researcher who gave us the exploit used by the Slammer worm) has been nixed.

Don't blame Oracle, though. Blame it on the price of gas.

For Litchfield, who was set to speak Thursday on Oracle Forensics at this year's Black Hat talk just wasn't meant to be. First the UK-based researcher lost his passport, then when he finally got around to booking his flight out to Las Vegas, he balked at the airline prices.

"I...  didn't see the point in coming across for just a day when the prices for  flights are as high as they are," he told me.

So what was he going to talk about? A new class of Oracle flaw and something called a dbms_assert  bypass attack. He said that Dbms_assert  "is a default plsql package that contains a number of functions  that can be used to validate user input - to stop things like sql injection."

"I've noticed that Oracle every so often uses one of these functions in such  a way that sql injection is still possible," he added.

Looks like show organizers have replaced his talk with: Windows Hibernation File for Fun and Profit, by  Matthieu Suiche

Ads by TechWords
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WHITE PAPER
Discover whether hosting is your smartest choice for enterprise messaging.

GoogleTo host or not to host? Thats the question for many CIOs as the volume and complexity of enterprise messaging continues to skyrocket.

» Read the Paper