vBulletin FAQ
The website where you learn about vBulletin Forums
Home   Download vBulletin   vBulletin FAQ Forums vBulletin Related Sites Contact Us
Welcome to vBulletin FAQ

vBulletin FAQ Navigation

Getting Started

Customizing your vBulletin

Search Engines & SEO

Making Money with a Forum

Promoting your Community

Get your own vBulletin Today


Webmaster Help


The Database Hacker's Handbook: Defending Database Servers





vBulletin Book Store > vBulletin books beginning with D

More details of book titled: The Database Hacker's Handbook: Defending Database Servers

The Database Hacker's Handbook: Defending Database Servers

Author: David Litchfield
Published: 2005-07-14
List price: $50.00
Our price: $31.50
Usually ships in 24 hours
As of: September 05th, 2008 06:37:02 PM
Customer comments on this selection.

vBulletin Coverage of many databases, but not as coherent as it should be
The Database Hacker's Handbook (TDHH) is unique for two reasons. First, it is written by experts who spend their lives breaking database systems. Their depth of knowledge is unparalleled. Second, TDHH addresses security for Oracle, IBM DB2, IBM Informix, Sybase ASE, MySQL, Microsoft SQL Server, and PostgreSQL. No other database security book discusses as many products. For this reason, TDHH merits four stars. If a second edition of the book addresses some of my later suggestions, five stars should be easy to achieve.

The first issue I would like to see addressed in a second edition of TDHH is the removal of the 60 pages of C code scattered throughout the book. The code is already provided on the publisher's Web site, and its appearance in a 500 page book adds little. The three pages of characters (that's the best way to describe it) on pages 313-315 in Ch 19 are really beyond what any person should be expected to type.

The second issue involves general presentation. Many chapters end abruptly with no conclusion or summary. Several times I thought "Is that it?" Chapters 2, 5, 7, 10, 13, 15, 18, 21 and 22 all end suddenly. The editor should have told the authors to end those chapters with summaries, as appear in other chapters. On a related note, some of the "chapters" are exceptionally short; Ch 9 and 12 are each 3 pages, for example. Chapters that short are an indication the book is not organized well.

The final issue involves discussion of various databases. I preferred the "Hacking Exposed" style of the 2003 book SQL Server Security, which included Dave Litchfield and Bill Grindlay as co-authors. That book spent more time introducing the fundamentals of database functions before explaining how to break them. For example, more background on PL/SQL would be helpful. With 60 pages of code removed, that leaves plenty of room for such discussion in the second edition.

On the positive side, I thought TDHH started strong with Ch 1. The Oracle security advice was very strong. I thought the time delay tactic for extracting bit-by-bit information from the database was also exceptionally clever.

Although I have not read it, I believe Implementing Database Security and Auditing by Ron Ben Natan might be a good complement to TDHH. Natan's book appears to take a functional approach, whereas TDHH takes a product-specific approach. The drawback of the product-centric approach is repetition of general security advice, such as enabling encryption, disabling default accounts, etc.

At the end of the day TDHH is still a revealing and powerful book. Anyone responsible for database security should refer to the sections of the book covering their database. I also recommend keeping an eye on the Next Generation Security Software Web site for the latest on database security issues. You should also see the authors speak at security conferences whenever possible.


vBulletin Just as good as I expected
So, there I was. I was about to buy a new book and I really had to think hard about what to buy - after reading The Shellcoders Handbook, I was really interested in grabbing a copy of this book, in the end, that's exactly what I did.

I am happy with my decision to the fullest extent. Not only was it a great brother to The Shellcoders Handbook, but it was also just good reading in general. It covers seven of the most popular databases around, and each section of the book goes over it's history, it's flaws, how to propogate after a successful exploit, and finally how to lock down your database. You'd be suprised at how easily and how asinine some of the flaws found in database servers are - it's almost laughable, some of the flaws that many servers have been prone to are ridiculous.

The book, like it's brother, covers information that is somewhat dependent on context, but the general concepts you will see and learn are going to remain relevent to all types of research related to the topic at hand for a long time to come.

If you own the Shellcoders Handbook -- or even if you don't --, you should not at all miss on this, The Database Hacker's Handbook: Defending Database Servers is something security enthusiasts everywhere should have on their shelfs.


vBulletin Dave is amazing!
Wow - I had to have this book. They are right, he explains everything wrong with Oracle and all about vulnerabilities and exploits.

vBulletin Important Book For Database and Security Admins
David Litchfield is arguably the foremost expert and evangelist when it comes to database security. He, and his team of compatriots from Next Generation Security Software, have written a book that any database or security administrator should be familiar with.

Even if some of the attacks or exploits described in the book were previously obscure or unknown, the fact that they have been outlined in this book means that administrators need to know about them and defend against them before the "bad guys" read this book and take advantage of them.

One of the best aspects of this book is the way it is organized. Splitting the book into sections devoted to specific database systems makes it exceptionally simple and convenient to use. If you only use MySQL, you can skip all of the information regarding Oracle or Microsoft SQL Server, and just focus on the section of the book that applies to you.

Within each section, the authors provide a tremendous wealth of knowledge. Aside from describing weaknesses, potential exploits and protective measures to defend against them, they also look at the general architecture and the methods of authentication used by the database.

Any database admin should have a copy of this on their desk.


vBulletin Attacking Database Servers
My review relates only to the Oracle chapters.

This is the first book to actually expose real Oracle hacks. Most security books are just glorified papers on Oracle security, written by people in grey suits with image consultants.

The real fun of this book is in the "Attacking Oracle" chapter. These guys gave the phrase "thinking outside of the box" real meaning. They look for a feature or bug open to the security attack, then they shake it until it breaks. You will see exploits of AUTHID, PL/SQL injections, app. server, dbms_sql.parse bug,... most of them relevant to 9i and 10g versions.

The hacks are mainly in the sections called "Real-World Examples". Most of the exploits are already patched by Oracle and they are also available on hacking forums, but there were some new ones that were quite a revelation.

The security recommendations in the "Securing Oracle" chapter were too general, you can probably find Internet white papers on hardening Oracle that give more details. But, this book is not really about hardening Oracle, even if it says "Defending Database Servers" with small, blue letters on the front cover. This book is about attacking database servers.

I have seen David Litchfield's previous work and I am sure he knows (and has tried) more than what is written here. Can we expect to see that in "The Hacker's Handbook" part II?


Similar Listings

Book cover of Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase.Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase
Book cover of The Oracle Hacker's Handbook: Hacking and Defending Oracle.The Oracle Hacker's Handbook: Hacking and Defending Oracle
Book cover of SQL Server Security.SQL Server Security
Book cover of The Shellcoder's Handbook: Discovering and Exploiting Security Holes.The Shellcoder's Handbook: Discovering and Exploiting Security Holes
Book cover of The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws.The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
Our vBulletin book picks:


Find more vBulletin related products of interest.

Search:
Keywords:
Amazon Logo

Purchase vBulletin - Site Map - vBulletin Forum
Copyright © 2006 vBulletin-FAQ.com. All rights reserved.
This website is not affilliated with Jelsoft or vBulletin.
Forums - Archive