Monday, November 19, 2007

News Commentary on "Hacker finds 492,000 unprotected Oracle, SQL database servers"

Hacker finds 492,000 unprotected Oracle, SQL database servers by ZDNet's Ryan Naraine -- A survey by renowned database hacker David Litchfield has found a whopping 492,000 Microsoft SQL and Oracle database servers directly accessible to the Internet without firewall protection.



Not having verified any kind of similar results and not being able to look at his results I cannot dispute what he found. However, I'm finding it difficult to believe that he picked 1.1 million IP addresses 'at random' and then of these, almost 32% were active open MS SQL servers. Some of this other statistics I'm also finding hard to swallow.



Not having verified the results, I can only give my option: FUD (Fear Uncertainty and Doubt), possibly with the goal of selling his products.

0 comments: