ORACLE Anti-Hacker-Training
Overview
Know your enemy is important if you are responsible for the protection of Oracle databases and Oracle application servers. In this training you learn various tricks of Oracle hackers and the appropriate countermeasure One part of the training is a capture-the-flag competition “Guy guys vs. bad guys”. Up to now the bad guys won in most cases...
Content 4 day training
Oracle Security Information Security Basics Oracle Books, Who is Who, Google Hacking, Metalink Hacking, Analyzing Oracle Security Patches, ... Secure Architectures, Oracle Security Features, Audit & Encryption, SQL Injection, ... Attack Scenarios, X11, Reading and stealing files, Oracle passwords, Database Encryption, Backdoor (how to implement and find), Hardening Oracle databases, Invisible Database users, ... Secure PL/SQL Programming, Policies, Source Code analysis Attack Scenarios, Passwords and accounts, analyzing Oracle clients, hardening Oracle clients, ... Oracle Viruses, Oracle Rootkits, Oracle Worms, Oracle Firewalls, Oracle Patch modification
Course Pre-requisites
Students should have good knowledge of Oracle databases (e.g. Oracle DBAs or Oracle Developer)
Course Material
English course notes (> 1500 pages) as PDF Bootable Security CD (Backtrack 2) with various Oracle tools from Red-Database Security (checkpwd, sidguess, ...)
Database
Practical Sessions
Each topic covered during the lectures will be illustrated during the practical session. Each student will try out the tools and techniques they learned in the class on the lab machines. Secure Development
Course Duration
4 days
Intended Audience
This course is not intended for misguided individuals who intend to use tools and techniques for criminal purposes • Database administrators that are keen to learn how a hacker would view their database deployments • IT consultants who want to learn to perform in-depth security assessments Oracle Clients
Advanced Topics
Red-Database-Security GmbH, Bliesstr. 16, D-66538 Neunkirchen, Germany, email: training@red-database-security.com