Black Hat: Shark-bitten security researcher takes another chomp out of Oracle database

A researcher scored again against Oracles database by demonstrating at the Black Hat security conference Thursday an exploit that would allow him to take control as an administrator.

David Litchfield, a researcher at Accuvant Labs, demoed what he called the PWNORACLE exploit against the Oracle 11g database, earning applause from his audience, some of whom also photographed the exploit code he projected on-screen.  In 2010 at a Black Hat event, Litchfield showed .

This weeks Litchfield demo was part of a larger presentation about Oracle database flaws pertaining to indexes.

Litchfield said he has already reported the vulnerability he discovered to Oracle and thought they would have fixed it by now.