Artwork

Content provided by Jeff Moss and Black Hat Briefings. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Jeff Moss and Black Hat Briefings or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Black Hat Webcast 6: Database Forensics with David Litchfield

1:21:21
 
Share
 

Manage episode 124695417 series 132021
Content provided by Jeff Moss and Black Hat Briefings. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Jeff Moss and Black Hat Briefings or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Database Forensics expert David Litchfield will discuss his new tool and paper with Black Hat Founder and Director Jeff Moss and take questions from our webcast audience. The tool, orablock, allows a forensic investigator to dump data from a "cold" Oracle data file - i.e. there's no need to load up the data file in the database which would cause the data file to be modified, so using orablock preserves the evidence. Orablock can also be used to locate "stale" data - i.e. data that has been deleted or updated. It can also be used to dump SCNs for data blocks which can be useful during the examination of a compromised Oracle box.
  continue reading

10 episodes

Artwork
iconShare
 
Manage episode 124695417 series 132021
Content provided by Jeff Moss and Black Hat Briefings. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Jeff Moss and Black Hat Briefings or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Database Forensics expert David Litchfield will discuss his new tool and paper with Black Hat Founder and Director Jeff Moss and take questions from our webcast audience. The tool, orablock, allows a forensic investigator to dump data from a "cold" Oracle data file - i.e. there's no need to load up the data file in the database which would cause the data file to be modified, so using orablock preserves the evidence. Orablock can also be used to locate "stale" data - i.e. data that has been deleted or updated. It can also be used to dump SCNs for data blocks which can be useful during the examination of a compromised Oracle box.
  continue reading

10 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play