infowarrior  

[infowarrior] - In the interest of helping journalists cover Oracle..

Richard Forno
Fri, 20 Jan 2006 04:52:05 -0800

(c/o Jericho)

http://www.osvdb.org/blog/?p=86

In the interest of helping journalists cover Oracle.. perhaps they should
just move to a templated form to save time?

---

By [YOUR_NAME]
[YOUR TITLE], [YOUR PUBLICATION]
[DATE]

Oracle released on [DAY_OF_WEEK] fixes for a [LONG/HUGE/MONSTROUS] list of
security vulnerabilities in [ONE/MANY/ALL] of its products. The quarterly
patch contained patches for [NUMBER] vulnerabilities.

Titled "Critical Patch Update", the patch provides
[FIXES/REMEDIES/MITIGATION] for [NUMBER] flaws in the Database products,
[NUMBER] flaws in the Application Server, [NUMBER] flaws in the
COllaboration Suite, [NUMBER] of flaws in the E-Business Suite, [NUMBER]
of flaws in the PeopleSoft Enterprise Portal, and [NUMBER] of flaws in the
[NEW_TECHNOLOGY_OR_ACQUISITION].

Many of the flaws have been deemed critical by Oracle, meaning they are
trivial to exploit, were likely discovered around 880 days ago, and are
trivially abused by low to moderately skilled
[HACKERS/ATTACKERS/CRACKERS].

"[DULL_QUOTE_FROM_COMPANY_WHO_DISCOVERED_NONE_OF_THE_FLAWS]" security
company [COMPANY] said yesterday as they upped their internet risk warning
system number (IRWSN) to [ARBITRARY_NUMBER]. "This is another example of
why our products will help protect customers who chose to deploy Oracle
software" [ARBITRARY_CSO_NAME] stated.

"[COMPLETELY_BULLSHIT_QUOTE_ABOUT_PROACTIVE_SECURITY_FROM_ORACLE"
countered Mary Ann Davidson, CSO at Oracle. "These hackers providing us
with free security testing and showing their impatience after 880 days are
what causes problems. If these jackass criminals would stop being hackers,
our products would not be broken into and our customers would stay safe!"

Oracle has been criticized for being slow to fix security flaws by
everyone ranging from L0rD D1cKw4v3R to US-CERT to the Pope.




You are a subscribed member of the infowarrior list. Visit 
www.infowarrior.org for list information or to unsubscribe. This message 
may be redistributed freely in its entirety. Any and all copyrights 
appearing in list messages are maintained by their respective owners.
  • [infowarrior] - In the interest of helping journalists cover Oracle.. Richard Forno