[24876] in bugtraq
Re: Oracle9i TSN DoS Attack
daemon@ATHENA.MIT.EDU (Lucien Fransman)
Fri Mar 29 15:47:11 2002
From: "Lucien Fransman" <l_fransman@hotmail.com>
To: <bugtraq@securityfocus.com>
Cc: "Andrey Gordienko" <red@rsh.kiev.ua>
Date: Fri, 29 Mar 2002 14:38:15 +0100
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Message-ID: <LAW2-OE43r6beUzmRf600004e8c@hotmail.com>
Hi.
I was wondering if the issue with the TNS listener you mention is the same
that has been reported in April 22, 2001 to this mailinglist ( see
http://marc.theaimsgroup.com/?l=bugtraq&m=98770470120424&w=2 for details)
(which is BTW the same as the vulnerability mentioned in this
(http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf )Oracle
advisory AFAIK).
I dont have access to a Oracle test database ATM, so if you would be so kind
to confirm or deny this, I would be very gratefull.
BTW, as this appered in Oracle 8 and prior versions, Oracle Corp has not
done their homework very well with newer releases :)
With Kind Regards,
Enchanter_tim