tag:blogger.com,1999:blog-4088979.post7994151828809900946..comments2023-10-16T06:06:25.012-04:00Comments on TaoSecurity Blog: Database ForensicsRichard Bejtlichhttp://www.blogger.com/profile/13512184196416665417noreply@blogger.comBlogger2125tag:blogger.com,1999:blog-4088979.post-57553787849720531602007-05-20T07:47:00.000-04:002007-05-20T07:47:00.000-04:00Very good paper...I addressed it on my blog. I se...Very good paper...I addressed it on <A HREF="http://windowsir.blogspot.com/2007/05/litchfield-on-oracle-live-response.html" REL="nofollow">my blog</A>. I see this as an excellent resource for folks who encounter an Oracle database in the course of their incident response.<BR/><BR/>The only thing I would suggest as a change in the paper is that the author consider, in the live response section, re-ordering the listing of information to be collected, taking the Order of Volatility (RFC 3227) into account.<BR/><BR/>Great job and kudos to David!H. Carveyhttps://www.blogger.com/profile/08966595734678290320noreply@blogger.comtag:blogger.com,1999:blog-4088979.post-40909540310899104802007-05-18T19:40:00.000-04:002007-05-18T19:40:00.000-04:00You are being too kind to Oracle. I'd say more lik...You are being too kind to Oracle. I'd say more like 7-10 years behind. What's humorous is the recent additions to their product line that add "new" features like audit vault that "simplify compliance reporting, proactively detect threats, reduce costs and secure audit data".<BR/><BR/>Oracle should be grateful for firms like NGS and others who are helping them secure their products. I have no idea what the Security people at Oracle are doing, but I'll give them the benefit of the doubt that politics and bureaucracy are in their way.<BR/><BR/>I am greatly irritate when I see the way Oracle treats people like NGS. What if David and friends weren't so kind? What happens when more people put their attention towards Oracle and decide they don't want to wait 2 years for Oracle to fix a bug but would rather screw Oracle over for being jerks and release 0days?<BR/><BR/>I know that they are making changes, but they have a LONG way to go.Anonymousnoreply@blogger.com